Sanitizing environment variables


Because correlation actions are often used with batch files, the values of environment variables are made safe (or sanitized) for Windows batch files by substituting or removing troublesome characters from the S_MESSAGE and other variables.

By default, environment variables are sanitized, but if you are executing another script interpreter (such as Python, Perl, or PHP), it is not necessary to sanitize the values.

To stop sanitizing environment variables

  1. On the Correlation > Actions tab, click to edit an action or add an action.
  2. Set Sanitize Environmental Variables to No.


Warning

Setting Sanitize Environmental Variables to No makes it risky or impossible to use the environment variable value anywhere within a Windows batch file.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*