Active list search problem
I have one problem with active list. I have an active channel which contains device custom string 1 field which contains dns query name. I want to create rule which will search my active list and which will do something if particular string is found in this active list. So I created event based active list with only one custom string 1 field. Modified rule to search this list. And the problem is that when I add only one entry into this list - everything works but if I add another entry it seems that events are correlated using only one value from this list and not the both values. So my question is - what am I doing wrong? I want my rule compare events with all custom string 1 values entered into this list.