Jul 27 2023 10:10 AM
I want to exclude windows EventID 4663 and ObjectType =file using runtime transformation. I applied below:
| where EventID != 4663 and ObjectType != "File"
but it removes all 4663 events rather removing based on objecttype which I made combination with eventid. please help. Thanks
Jul 28 2023 03:53 AM
Jul 28 2023 06:01 AM - edited Jul 28 2023 06:02 AM
Solutionyes, thats exactly I wanted. Thank you so much for your help.
Jul 28 2023 06:01 AM - edited Jul 28 2023 06:02 AM
Solutionyes, thats exactly I wanted. Thank you so much for your help.