Hell @audit_4852,
I’ve just started a new discussion Write audit_log_filter definitons about writing rules for this component. In your case I think something like this can help you :
{
"filter": {
"class": [
{
"name": "query",
"event": {
"name": "start",
"log": {
"or": [
{ "field": { "name": "sql_command_id", "value": "select"} },
{ "field": { "name": "sql_command_id", "value": "create_table"} },
{ "field": { "name": "sql_command_id", "value": "drop_table"} }
]
}
}
}
]
}
}