We have notable events for when a user is created on multiple devices. Most of them are expected for when devices are imaged.
I want to use erex to create a suppression for like accounts. They typically have the same beginning and are followed by 2 numbers. Example would ituser23, ituser24, ituser25.
I am using the search below for testing
index=notable source="Endpoint - Anomalous User Account Creation - Rule" | erex user examples="ituser23, ituser24, ituser25"
I am still getting user accounts that are unrelated such as phone or tablet.
When I look at the recommended regex it seems like it is not being granular enough.
... View more