I have created a rule to detect whenever there is a successful VPN
login. I have the incident title set as:"Successful VPN login from $user
at IP $srcIpAddr to $userGrp" However, the "$userGrp" attribute is not
displaying as expected. Instead, it com...
Hi Stephen, Thank you for your assistance and those suggestions. I can
confirm that the User Group attribute is definitely pulling through the
right data, as I have used it in the SubPattern definition for my rule,
to exclude VPN logins for a particu...