Hi All,
I am working on creating a User Defined Event for long standing DNS connections (potential exfil operations)
When creating the event, I don't get an option to define login for an "Over" amount of duration like >200 seconds as an example.
I cannot seem to get an event to generate when testing, the times can only be equals, being an exact number.
Has anyone had any success with creating a user defined event for connections over a specific duration? How did you do it? I also want to do the same for high bandwidth sessions and I am also stuck with equals and no over/under.