I want to filter some events based on the occurence of multiple matchs, for instance, I want to match all (Windows) events that match (EventCode=566) AND simultanously match also (keyword=success)
Of course, I still need to do more matchs on the REGEX (Theses are working fine using the | operator), but the issue is really with doing an AND.
Any advice ?
I'm using the method described in the link to discard specific items and keep the remaining logs.
Below is REGEX l'm actually using:
I want to add somme supplementary checks for specific eventcodes like searching for another string (the search should be done only when specific eventcodes are matched)
I was planning to use REGEX like the one below but i doesn't match at all: