Hi everyone,
I’m trying to drop all CrowdStrike logs except those that contain the tag SensorGroupingTags/ABC.
I’ve configured an event-dropping rule as shown in the screenshot, but I’m still receiving all CrowdStrike logs instead of only the ones with the specified tag.
Has anyone encountered this issue or can point out what might be wrong with the rule logic?
Regex: ^(?!.*SensorGroupingTags/ABC).*
Hi @doosa
I don't see a screenshot nor have I worked with CrowdStrike logs, but your regex looks suspicious. Question marks have a special meaning (= optional occurence of preceding character). Putting it after a parenthesis (= creating a back-reference), does not make sense to me. Posting a sample log may help to understand what you try to match.
| User | Count |
|---|---|
| 2913 | |
| 1452 | |
| 852 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.