PatternDB not working as expected. Config errors?

Hi there,

I'm having a little trouble trying to filter events with patterndb.xml

I'm sending logs to our SIEM but despite the corresponding event ID's missing from patterndb they are still getting pushed.

I think my configuration setup is over ruling the patterndb config.

Can you please review?

Thanks for your time.

AskedFebruary 19, 2020 - 4:39am