San-SecTech
Saturday, May 25, 2019
splunk
Username from linux secure:
for(?:\suser)?(?:\sinvalid user)?\s(?<user>\S+)
NOT vs !=
if the field does not exist in a row. then row will not be included for "!=", however NOT search will include rows which do not have that field.
No comments:
Post a Comment
Newer Post
Older Post
Home
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment