Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L4 Transporter

You can add an OR to the filter and use parenthesis to group your operators, like so:


| filter (action_local_ip = "" and action_local_port != 445) or action_local_ip != ""


This selects either logs where the local IP is and the source port is not 445, or logs where the local IP is not

View solution in original post

Who rated this post