A RegEx-based compliance test configured with Match type "Contains" and a pattern that should flag a violation (e.g. logging <IpAddress>) instead marks devices containing that line as compliant, when the intent is for its presence to mark the device non-compliant.
On the Rule tab, Match type "Contains" is designed so the test/step passes (compliant) when the pattern is found in the device configuration — it does not mark presence as a violation.
There is no invert/negate toggle on the Rule tab itself; pass/fail-on-presence logic is controlled separately, on the Scope tab.