When creating a Syslog Alert in Orion in the Syslog Message Pattern section if I use a list of message patterns as provided in the examples at the bottom; is the list of comma separated values using an AND or an OR for those different patterns?
Example:
*Deny UDP*, *Accessed URL*
In this case do both patterns need to exist to trip the alert or is it looking for just one of them to exist?