09-06-2007 04:28 AM - edited 03-10-2019 03:46 AM
Regarding Event Action Filters. How do you add multiple event variables to the attacker and victim fields? I use a comma to separate IP addresses (10.10.1.1,192.168.1.1). When I use a variable ($inside) I have not been able to add any other IP addresses or variables ($dmz) in the same filter rule. Is it possible to have two variables in the same attacker/victim fields? I would have thought $inside,$dmz might work but I get an error. I have also tried $inside\,$dmz and $inside ,$dmz and $inside \,$dmz but get errors saying system variable not found.
Solved! Go to Solution.
09-06-2007 06:28 AM
Only one variable is currently allowed in a field.
There is an enhancement request to support multiple variables in a field, but this has not been targeted for any specific release yet.
09-06-2007 06:28 AM
Only one variable is currently allowed in a field.
There is an enhancement request to support multiple variables in a field, but this has not been targeted for any specific release yet.
07-08-2013 05:58 PM
I was surprised to see this discussion from 2007 when it still appears to be the case in 2013 of only one event variable per field. Is there a specific decade targeted for this enhancement?
Thanks,
Mark
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide