Skip to main content

help with Query

  • October 8, 2024
  • 1 reply
  • 13 views

rahul7514
Forum|alt.badge.img+10

Hi 

In my log for Crowdstirke i am facing an issue 

security_result.action = Block is seen when i am export the UDM events . However when i am searching the same field inside Chronicle it is seen as . As a result when i am building the query with this logic security_result.action = Block some of the events are triggering although action = blocked , how to fix this issue ?
security_result[1].action[0] = "BLOCK"

1 reply

AymanC
Forum|alt.badge.img+14
  • Bronze 5
  • October 9, 2024

Hi @rahul7514,

The below response in your other topic should help - Re: help with Query - Google Cloud Community

Kind Regards,

Ayman