How to use Event Date field in correlation rules?
I want to create incident if some specific event / or events will occur within certain time frame, i.e. every successfull logon attempts from one source IP address between 10 pm and 6 am.
I wanted to use Event Date field with 'matches' operator and regex patterns such as ^\d\d\d\d\-\d\d\-\d\d\s22:\d\d:\d\d.*$ and so on. But it doesn't work, I received "XML Parse Error"
I noticed that I can put there only numbers no matter what operator is being used.
Also I found a field called Event Day, but if I'm correct this field can be used only when we want to use Weekdays or Weekend lookup tables. Unfortunatelly, there is no field such as Event Hour etc.