I have created a pipeline for filtering data coming into the sourcetype = fortigate_traffic.
I would like to further add an exclusion to the data coming into this sourcetype. How can this be done? Nested ? or any other method
eg;- 1st pipeline is
Hey @Rani2,
I haven't tested it myself. But can you not combine two conditions using AND?
Thanks,
Tejas.