How to best exclude false positives that are not fully specified through the Message field?
Example of log messages generated when vulnerability scanners such as OpenVAS are running:
MODULE:
LogScan
MESSAGE:
Suspicious Log Entry found
ENTRY:
..."GET /dotcms/html/portal/login.jsp HTTP/1.1" 200 8506 "-" "Mozilla/5.0 [en] (X11, U; OpenVAS-VT 22.7.3)"
The thor false positives filter is just using the Message field value, and I would assume that this then filters ALL suspicious log entry findings, which would be too much. Is there a way to filter simultaneously on the Message AND on the Entry field? Or what would be a suitable solution?