Thank you for the response. So, if I am understanding this correctly
trying to create an app rule or esa rule for the log decoder wont detect
this right away?
I see the two app rules you have here. They look to be for the packet
decoder. If I was to do this on a log decoder or the endpoint log
decoder would the below work: (port = 80) && (action = 'post') && (query
contains '**') (port = 80) && (filename r...