Does anyone have a good workaround for this issue?
tried many of the former suggestions in this forum, like in here (https://community.mcafee.com/t5/Security-Information-and-Event/Is-there-any-way-to-filter-destinatio...)
but nothing capture correctly. I still left with null values.
Since the thread is also a bit old, has anyone overcome this issue and can help?
Thank you
[McAfee 11.3 version]
Have you checked the resolutions given in the below community post?
Regards,
Prashanth B Pillai
McAfee Technical Support
Customer Success Group
Hi Prashanth
thank you for reaching out
I did. when using query filter "source user = regex ($)" I'm getting only fields that contain values, so that OK.
BUT, what is the most efficient way or correct way to implement it within a correlation rule?
source user could be "in" or "not in" ONLY conditions
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA