AnsweredAssumed Answered

What is the syntax for the 'begin' operator in a Rule clause?

Question asked by Jdhahn on Mar 19, 2014
Latest reply on Mar 21, 2014 by Jdhahn

For example, Rule Test with the following query :

 

device.type = "winevent_nic" && alert.id =  "access:privilege-escalation-success" && ip.addr = "13.101.134.216"

 

returns 12 values. However, Rule Test with the following query (same exact time range):

device.type = "winevent_nic" && alert.id =  "access:privilege-escalation-success" && ip.addr begins "13.101."

 

returns "No Values Available For The Rule."

Outcomes