Hi,
how is it possible to structure syslog sensor filters when we need to combine and with or: severity[0-6] AND source[10.133.14/255] OR source[172.16.0/255]
In that example I would like to have the include filter for severity 0-6 and the source ip of the switch shell be 10.13.14.x or 172.16.0.x.
Would that expression also work outside the local probe device? Can there be another local probe device within another structure (we have a separation between office/production and network devices within the local probe.
Best Regards,
Joachim
Add comment