7 Replies Latest reply on Aug 4, 2017 4:36 PM by r_gine

    Correlation rules and regex/contains filter options

    robert_dearbytes

      A very simple question but having a hard time to find the answer. Can a correlation rule -> match component contain regex or contains() filters to trigger on a part of a value?

       

      example: contains(admin) for a source user.

       

      If not, are there any other ways to trigger on a part of a value in a correlation rule?