Forum Discussion
securityxpert1122
Jul 27, 2023Copper Contributor
Runtime transformation in Sentinel
I want to exclude windows EventID 4663 and ObjectType =file using runtime transformation. I applied below:
| where EventID != 4663 and ObjectType != "File"
but it removes all 4663 events rather removing based on objecttype which I made combination with eventid. please help. Thanks
yes, thats exactly I wanted. Thank you so much for your help.
- KubaTomBrass Contributor
- securityxpert1122Copper Contributor
yes, thats exactly I wanted. Thank you so much for your help.