
Mark Drummond
- Total activity 66
- Last activity
- Member since
- Following 0 users
- Followed by 0 users
- Votes 11
- Subscriptions 16
Activity overview
Latest activity by Mark Drummond-
Mark Drummond commented,
Hi Stephen. We're just documenting session info for all our apps, idle vs. absolute timeouts, are the timeout configurable etc., as part of a policy review. I seem to recall there is a longer term ...
-
Mark Drummond commented,
Thanks Stephen. Exactly what I needed to know. Cheers,Mark
-
Mark Drummond created a post,
Is Max Web Session timeout an idle timeout, or fixed / absolute?
https://help.sumologic.com/docs/manage/security/set-max-web-session-timeout/ Is the Max Web Session timeout setting an idle timeout (terminate session after X minutes / hours / days of inactivity) ...
-
Mark Drummond commented,
That worked, thanks!
-
Mark Drummond created a post,
Geo lookup on "data.ip OR ip"
Due to a change in log format, the IP addresses I want to do a geo lookup on might be stored under "data.ip" for new logs, or just "ip" for older logs. I want to do the equivalent of: | lookup lati...
-
Mark Drummond created a post,
Log access defaults to allow all?
Is it my imagination or is the default log access behaviour in Sumo "allow all"? It seems to me that, in order to limit someone's access to logs, I must assign them at least one role that limits th...
-
Mark Drummond created a post,
Searching from a list of keywords
Example: "I need all log entries related to users 'jane', 'john', 'alice', and 'bob'." Given a list of user identifiers, search my logs for log entries that match any of the user identifiers in the...
-
Mark Drummond created a post,
Understanding search filters
ref: https://help.sumologic.com/Manage/Users-and-Roles/Manage-Roles/Construct-a-Search-Filter-for-a-Role Just looking for some confirmation of my understanding of filters on roles: Scenario: Imagin...
-
Mark Drummond commented,
That put me on the right path. Here is what I ended up with (apologies for the link ... cut and paste is not working for me and I'm not going to type it out here): https://pastebin.com/DKkJQZAv I w...
-
Mark Drummond commented,
Hi Mario. I am using the Cloudflare app, but the WAF Rules Triggered query is just pulling the WAFRuleID field, which is not what I am looking for. The most common WAFRuleID is "981176", which is a...