Hello,
Sorry if this question had been posted in the past. I looked through the posts for Wildcard and most of them seem to be related to configurations.
I was looking to see if there's possibly a way to add a wild card to a filter on the events. For example, let's say I wanted to filter out WinExecutable for all users users on data.win.eventdata.processName:
C:\\Users\\ABC\\Desktop\\WinExecutable.exe
C:\\Users\\DEF\\Desktop\\WinExecutable.exe
C:\\Users\\GHI\\Desktop\\WinExecutable.exe
C:\\Users\\JKL\\Desktop\\WinExecutable.exe
How could I change the filter to just be something like: C:\\*\\WinExecutable.exe?
I know it will probably have to be done in DSQL, but I have tried an asterisk (*), Amersand (&), Percentile (%) and nothing seems to work.
Thank you.