23-11-21 06:23 AM
24-11-21 10:46 AM
file {
path => "c:\allevents.txt"
codec => line { format => "%{event}"}
}
}
Once you get it working then see if using OR clause works?
if [event][EventType] == 1 and (([event][EventData][ProcessName] == "process1") or ([event][EventData][ProcessName] == "process2")) {
Regards
Pritam