Skip to content

TAU rules usage #113

Answered by alexkornitzer
PhilippRieth asked this question in Q&A
Nov 6, 2022 · 3 comments · 1 reply
Discussion options

You must be logged in to vote

Ah apologies I missed that there was = on the paul one it shoud be:

--tau 'Event.System.EventID: =4672' --tau 'Event.EventData.SubjectUserName: paul'

You are correct in that the full expressional logic should be added to Chainsaw but this has not been done yet as the parsing is a bit complex vs what is provided in Tau. I will see if I can add that to my todo list.

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@PhilippRieth
Comment options

Answer selected by alexkornitzer
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
bug Something isn't working
2 participants