@doosa It may well be that FortiSIEM does not support lookahead
assertions in the regex filters in this context. I sure haven't seen
them and couldn't find any FortiSIEM documentation about it either.
Unfortunately I have no FortiSIEM available to qu...
Hi @doosa I don't see a screenshot nor have I worked with CrowdStrike
logs, but your regex looks suspicious. Question marks have a special
meaning (= optional occurence of preceding character). Putting it after
a parenthesis (= creating a back-refere...
I'm not sure, as I haven't worked with it for a few years. I just had
that link readily available when I saw your post.
:smiling_face_with_smiling_eyes:Please study the technical tip: How to
check communication between collector and super from collec...