There are several flaws in the HP ArcSight Logger search capabilities that cause it to provide invalid search results for any query that uses boolean expressions. This means that any query to search through data in the logs ArcSight collected is potentially incorrect if the query contains more than one search term. Continue reading...