Example rex
|rex ".*\"LastmodifiedBy\":\s\"(?<LastmodifiedBy>[^\"]+)\""
|rex ".*\"ModifiedDate\":\s\"(?<ModifiedDate>[^\"]+)\""
|rex ".*\"ComponentName\":\s\"(?<ComponentName>[^\"]+)\""
|rex ".*\"RecordId\":\s\"(?<RecordId>[^\"]+)\""
... View more
I've got this problem, too. Disabling searches feels like a workaround. It's kinda hard to tell which ones you "need" and which you don't. You don't, for instance, need a saved search about a WSA if you don't have a WSA. But your "Top Attackers" search doesn't matter until you get attacked.
... View more