cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

Filtering question

I would like to use a wildcard search in a filter.  Is this possible?

I would like to filter on object name with *ZeroAccess*

and get back

ZeroAcess

ZeroAcess.ee

ZeroAcess.eh

ZeroAcess.cfg

etc....


Thank you!

2 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Filtering question

Hi cpedrick

The wildcard functionality has been requested by other customers and PM are aware that it would be a useful feature. But until that is available there is another option which should help you and that is "String Normalization"

If you search in the Help menu for that you will see a section under View Filters. There is a lot of detailed information and this is from the introduction;

The string normalization feature allows you to set up a string value that can be associated with alias values, to import a .csv file of string normalization values, or to export a file of . This enables you to filter on the string and its aliases when needed. In the case of the John Doe user name string, you would define a string normalization file where the primary string is John Doe and its aliases are, for example, DoeJohn, JDoe, john.doe@gmail.com, and JohnD. You could then enter John Doe in the User_Nickname filter field, select the string normalization filter icon (1-StringNormFilterIcon), and click on Run Query (1-runqueryIcon). The resulting view would show all events associated with John Doe and his aliases, enabling you to check for login inconsistencies where source IPs match but user names do not. This feature can also assist you in meeting regulations requiring that you report privileged user activity (e.g., PCI).

Chris

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 3

Re: Filtering question

You can also use dynamic watchlists to create filters using regex/wildcard syntax that are saved, automatically updated based on a user defined schedule, and once created, available from the filters in the global filter list. 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community