sourcetype="apache-access" | rex "(?i)\(.*?; (?P
i'm using the above to get information about bots.
how exactly can i modify the above to exclude certain bots????
i've tried:
sourcetype="apache-access" | rex "(?i)\(.*?; (?P
can someone please help me modify the above so it does exactly what i need. i just need to be able to exclude certain bots.
sourcetype="apache-access" | rex "(?i)(.*?; (?P
sourcetype="apache-access" | rex "(?i)(.*?; (?P