Friday, January 15, 2021

Palo Alto Log Filter

Hi All,

Anyone know if there is a way to filter on the name category under the threat logs for a keyword and not the full string? I can't figure out the proper syntax and I have to believe they'd include that so we don't have to sift through pages and pages of junk to find what we're looking for. For example, I want to see every threat alert that came in with keyword "macro" in the name field, but when I try to build a filter, there is no contains, only equal or not equal.



No comments:

Post a Comment