You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/user/bots.rst
+8-2Lines changed: 8 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2194,7 +2194,7 @@ Both parameters accept string values describing absolute or relative time:
2194
2194
2195
2195
* absolute
2196
2196
2197
-
* basically anything parseable by datetime parser, eg. "2015-09-012T06:22:11+00:00"
2197
+
* basically anything parseable by datetime parser, eg. "2015-09-12T06:22:11+00:00"
2198
2198
* `time.source` taken from the event will be compared to this value to decide the filter behavior
2199
2199
2200
2200
* relative
@@ -2204,7 +2204,7 @@ Both parameters accept string values describing absolute or relative time:
2204
2204
2205
2205
*Examples of time filter definition*
2206
2206
2207
-
* ```"not_before" : "2015-09-012T06:22:11+00:00"``` events older than the specified time will be dropped
2207
+
* ```"not_before" : "2015-09-12T06:22:11+00:00"``` events older than the specified time will be dropped
2208
2208
* ```"not_after" : "6 months"``` just events older than 6 months will be passed through the pipeline
2209
2209
2210
2210
**Possible paths**
@@ -3003,6 +3003,12 @@ The following operators may be used to match events:
3003
3003
* `:supersetof` tests if the list of values from the given key is a superset of the values specified as the argument. Example for matching hosts with at least the IoT and vulnerable tags:
* `:before` tests if the date value occurred before given time ago. The time might be absolute (basically anything parseable by pendulum parser, eg. “2015-09-12T06:22:11+00:00”) or relative (accepted string formatted like this “<integer> <epoch>”, where epoch could be any of following strings (could optionally end with trailing ‘s’): hour, day, week, month, year)
3007
+
``if time.observation :before '1 week' { ... }``
3008
+
3009
+
* `:after` tests if the date value occurred after given time ago; see `:before`
3010
+
``if time.observation :after '2015-09-12' { ... } # happened after midnight the 12th Sep``
3011
+
3006
3012
* Boolean values can be matched with `==` or `!=` followed by `true` or `false`. Example:
0 commit comments