I have a saved search that is returning results for URLs that I am expecting to see. I would like to exclude these results by using a partial match or whatever would be deemed best practice. Below the screenshot is the query.
_sourceCategory = symmetrylending/prod/network/meraki/* urls
| parse regex " (?<name>\S*?)\s(?<msg_type>urls|flows|events|ids-alerts|security_event|airmarshal_events?)\s+" nodrop
| kv regex "=(.*?)(?:\s|$)" "src", "dst", "mac" as src, dst, mac_address nodrop
| kv "agent" as user_agent nodrop
| parse "request: * *" as method, url nodrop
| parse field=src "*:*" as src_ip, src_port nodrop | parse field=dst "*:*" as dest_ip, dest_port nodrop
| where msg_type="urls" AND url !="https://dev-prod05.conferdeploy.net/..."
| count as Requests by url
| top 10 url by Requests, url asc
Please sign in to leave a comment.