Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
doosa
New Contributor

Unable to drop events Under event Handling.

Hi everyone,

 

I’m trying to drop all CrowdStrike logs except those that contain the tag SensorGroupingTags/ABC.

I’ve configured an event-dropping rule as shown in the screenshot, but I’m still receiving all CrowdStrike logs instead of only the ones with the specified tag.

Has anyone encountered this issue or can point out what might be wrong with the rule logic?

 

Regex: ^(?!.*SensorGroupingTags/ABC).*

@Gabe_FTNT  @Secusaurus @AEH 

 
 

 

 

1 REPLY 1
Gabe_FTNT
Staff
Staff

Hi @doosa 

I don't see a screenshot nor have I worked with CrowdStrike logs, but your regex looks suspicious. Question marks have a special meaning (= optional occurence of preceding character). Putting it after a parenthesis (= creating a back-reference), does not make sense to me. Posting a sample log may help to understand what you try to match.

--
Gabriel Kaelin, Sr. Enterprise Systems Engineer, Fortinet
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors