Hi,
I want to search for any "virus" event in a two different subtype. Is it possible?
Thanks,
You can try like this
(index=A1 sourcetype=S1 type=traffic,subtype=forward) OR (index=A2 sourcetype=S3 type=utm,subtype=virus) | search <<your condition/filter/criteria to find virus>>
Where A1-S1 and A2-S2 are index-sourcetype combination for different subtype
You can try like this
(index=A1 sourcetype=S1 type=traffic,subtype=forward) OR (index=A2 sourcetype=S3 type=utm,subtype=virus) | search <<your condition/filter/criteria to find virus>>
Where A1-S1 and A2-S2 are index-sourcetype combination for different subtype
What do you mean by subtype ? is this event type ?
Yes. That's what I mean.
That depends completely on what eventtypes you have, what your definitions are for "virus events", and a number of other factors. Please provide more details with log samples and fields, and we'll stand a better chance of helping you.
I want to manage logging from my fortigate firewall. There are two subtypes where fortigate is detecting a virus type of event. First is coming from "type=traffic,subtype=forward" and the other one is from "type=utm,subtype=virus" . I want to search for any virus from those two different subtypes? Is it possible?
Thanks,