Defining rules for audit log filter component (v8.0 / 8.4)

Hell @audit_4852,

I’ve just started a new discussion Write audit_log_filter definitons about writing rules for this component. In your case I think something like this can help you :

{
  "filter": {
    "class": [
      {
        "name": "query",
        "event": {
          "name": "start",
          "log": {
              "or": [
                { "field": { "name": "sql_command_id", "value": "select"} },
                { "field": { "name": "sql_command_id", "value": "create_table"} },
                { "field": { "name": "sql_command_id", "value": "drop_table"} }
              ]
          }
        }
      }
    ]
  }
}