What is a one sentence summary of your feature request?
We are looking to remove read events for a specific service account
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
We still want to see if the service account is preforming write, update or delete operations.
How do you currently solve the challenges you have by not having this feature?
We currently filter out all activity for this user
Hi Paul,
Thank you for the idea. It’s a valid request, and we’ve heard it from other customers as well. The current filtering capabilities don’t support this type of condition.
There is a workaround. You can create two outputs:
- Output 1: Monitors all operations except Read, without excluding any accounts.
- Output 2: Monitors Read operations only, with the service account excluded.
Both outputs must point to the same destination (log file, syslog, etc.).
If you’re using Legacy Access Analyzer, make sure only one of the outputs has the “This log file is for Access Analyzer 12 or earlier” flag enabled — it doesn’t matter which one.
The workaround does the job, but it can be hard to manage when you have a large number of monitored sources. The good news is this is already on our roadmap, though I can’t share an ETA at this point.
Thanks,
Paul