Hi I am creating a rule in enterprise security and am trying to use multiple tags.
| eval tag="prod_alert" and
| eval tag="risk_information"
What happens is every time the search runs the second tag overwrites the first tag. What do I need to do differently to use multiple tags in a rule?
I've never seen tags set at search time. Typically, they're tested at search time using (tag=prod_alert AND tag=risk_information
, for example.
Setting tags usually is done via eventtypes, but not a search time.
Thank you for your comment it made me realize I was going in the wrong direction.
I didn't' need a tag. Instead, I made a search macro and set prod_alert=1 which allows me to search that field.