You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe a specific use case for the enhancement or feature:
Basically allow network processor condition to support arrays as host.ip tend to return an array
Workaround if filter for network is /24 ie network mask255.255.255.0 is simple as this mean matching first 3 digits of IP address - however this is much more complicated if network filter were/25 for example meaning last digit contains 2 subnets
The text was updated successfully, but these errors were encountered:
Describe the enhancement:
Not sure if this should be considered bug or enhancement
At the moment
network
processor condition does not work on arrays and documentation is not clear on what type of data it supportsexample using auditd integration with these processors (tested with latest
8.16.1
) :contains works but network processor does not match in document
Debug logs contain "message": "Invalid IP address in field=host.ip for network condition" :
Describe a specific use case for the enhancement or feature:
Basically allow network processor condition to support arrays as
host.ip
tend to return an arrayWorkaround if filter for network is
/24
ie network mask255.255.255.0
is simple as this mean matching first 3 digits of IP address - however this is much more complicated if network filter were/25
for example meaning last digit contains 2 subnetsThe text was updated successfully, but these errors were encountered: