Hi @doosa I don't see a screenshot nor have I worked with CrowdStrike
logs, but your regex looks suspicious. Question marks have a special
meaning (= optional occurence of preceding character). Putting it after
a parenthesis (= creating a back-refere...
I'm not sure, as I haven't worked with it for a few years. I just had
that link readily available when I saw your post.
:smiling_face_with_smiling_eyes:Please study the technical tip: How to
check communication between collector and super from collec...
Hi IsuruI don't find any BarracudaWebFilterParser on my FortiSIEM 6.3.2
instance: Yet, the log message you posted originally passes the system's
BarracudaWAFParser:The only issue I see with the parser is that it does
not correctly categorize the ERRO...