Forum Discussion

rurno's avatar
rurno
Copper Contributor
Aug 18, 2020
Solved

Use "where contains" from a list

Hello,   I have been trying to setup Linux audit logs in Azure Sentinel, using the OMS auditd parser found in the OMS agent. (Not AUOMS, which I can't use as I have isolated servers).   Anyone wh...
  • mergene's avatar
    mergene
    Aug 18, 2020
    you can use "not (fieldname has_any(dynamiclist))"

Resources