I’m trying to create some definitions for Events, and I can get search results using the Search page, but when I use the same search in the Search Query, I do not receive any (or the same) results.
I’m specifically searching Palo-Alto 9 logs. Some examples:
These work in Search, but not in the Search Query in the Event Definition:
I can get this one to work in Search Query, but it leaves out any that are “medium-risk,unknown”:
http_url_category contains “medium-risk”
I’ve looked through the documentation and searched the forum, but haven’t found anything similar.
What would be the appropriate syntax to get a queries similar to: