Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Agust
Contributor

Combine Log Exporter filters

Hi guys!

 


We are looking to implement two combined filters for log exporter.
On one side we have the following filter that we want to apply:
# cp_log_export set name "name" filter-blade-in TP

and on the other hand we also want to export to the server the logs of the audit type.
Is there a way to combine both?
Thank you.

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Just to confirm what you're intending, you want to send both audit logs (all of them) and Security Logs that are for a specific blade?
In this case, you may need to create two connections to the same server, one that just sends audit logs (no filter) and one that has the specific filter for security logs.

0 Kudos
Agust
Contributor

Hello Phoneboy.
Thank you for your reply
We currently apply a filter for Threat prevention blades using the following filter

#cp_log_export set name qradar filter-blade-in TP

As you say we should generate another configuration in parallel to the target server that bears another name different from "qradar" and have applied the filter to send only audit logs?

Regards!

0 Kudos
PhoneBoy
Admin
Admin

I believe this is the only way to achieve this.

0 Kudos
Upcoming Events

    CheckMates Events