Forum Discussion
rurno
Aug 18, 2020Copper Contributor
Use "where contains" from a list
Hello, I have been trying to setup Linux audit logs in Azure Sentinel, using the OMS auditd parser found in the OMS agent. (Not AUOMS, which I can't use as I have isolated servers). Anyone wh...
- Aug 18, 2020you can use "not (fieldname has_any(dynamiclist))"