2 of 2 people found this helpful
Your condition for a filter/rule would look something like this:
Assuming you are collecting logs from a proxy/firewall/router to obtain information on URL hits? Can you see those logs within LEM? If so, you could be able to filter based on WebTrafficAudit & the source machine field should contain information on the hostname (or at least the IP address) of the 'click source'
This is generally how a WebTrafficAudit appears in LEM:
Ahh I was so close! Thank you for the help. it's working like a champ.