1 of 1 people found this helpful
I'm not sure this is possible without a bunch of rules because the wildcards I think it would match any of them and add to the counter triggering everytime.
It might be easier for you to create one rule that works how you want it to, then export that rule, change the fields how you need, then import the rule with the other settings. That way the log would only match and count correctly.
Although the syslog viewer is pretty snappy so it might be just as easy to manually add the rules.
I was thinking the same thing, just wanted to make sure.