First, sorry for my bad english!
When I create a trigger and use "and", "or", the status of trigger becomes UKNOWN
When I create a trigger and use "and", "or", the status of trigger becomes UKNOWN
{RHEL-B:log[/var/log/secure,sshd,,,skip].regexp(error:|Wrong password)}=1 and {RHEL-B:log[/var/log/secure,sshd,,,skip].nodata(3m)}=0
Comment