Skip to content

Commit 7d6c0e1

Browse files
author
Ruben van Vreeland
committed
Key by ip, ua
1 parent da5d4cb commit 7d6c0e1

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

rule_templates/relevant_attack_template.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,11 @@ filter:
1515
index: bitsensor-detections-*
1616
timestamp_field: endpoint.localtime
1717

18+
# Key per profile
19+
query_key:
20+
- context.ip
21+
- context.http.userAgent
22+
1823
# When the attacker continues, send a new alert after x minutes
1924
realert:
2025
minutes: 10

0 commit comments

Comments
 (0)