I'm attempting to create a rule that will ingest a list of partial hostnames and spit out their associated IPs based on DNS traffic traffic.
When attempting to run it, I get the following error (Broker name and IP redacted)
I've gone through the logs and there are no more details. If there is only one line in the list, it works fine. However, when there are multiple values/lines in the list, I get this error.
I assume I'm missing something obvious.
can you post some samples what is in the list?
Are the list values quoted with single quotes?
Thank you! That was it.