Latest reply on Aug 4, 2017

    Correlation rules and regex/contains filter options


      A very simple question but having a hard time to find the answer. Can a correlation rule -> match component contain regex or contains() filters to trigger on a part of a value?


      example: contains(admin) for a source user.


      If not, are there any other ways to trigger on a part of a value in a correlation rule?