Hello All, I'm trying to run query that will allow me to exclude events with part of a file path built in a windows event. The event looks like this
alert: %PlaceStuffIsStored%\ANYTHING\STUFF\And\Things\Blah\Blah\Blah\Blah.EXE was allowed to run but would have been prevented from running if the AppLocker policy were enforced. I was able to Rex out the file path to now I have a new field called path which is Dir
Dir=%PlaceStuffIsStored%\ANYTHING\STUFF\And\Things\Blah\Blah\Blah\Blah.EXE
I've tried the basics but no luck
Search!="*ANYTHING\STUFF\*" |mysearch Not (Dir="*ANYTHING\STUFF\*")
Thanks
You may need to escape your backslashes. Does the following work?
<original_search>
| rex <extract Dir field here>
| search Dir!="*ANYTHING\\STUFF\\*"
Whether you use != or NOT as your exclusion operator is up to you - but understand that they may return different results. Check the article Difference between != and NOT for more details.