i am trying to get a syslog alert fired when a sql query is matched. I can see the traps coming through the NPM and want a syslog alert when this happens.
I created the below sql query but it doesn't work. if I test it , it works fine, but its not matching the trap
also, wanted to know how to negate this as well
see the below query.

thank for your help