Commit 09207ee
[Rule Tuning] Elastic Agent Service Terminated (#5272)
* rule-tuning: Elastic Agent service termination improve for detection
* [Rule Tuning]: Elastic Agent Service terminated, updated date field
* Enhance detection rules for stopping Elastic Agent
* Fix syntax for process name checks in TOML file
---------
Co-authored-by: Ruben Groenewoud <[email protected]>
(cherry picked from commit 21217e5)1 parent 610729d commit 09207ee
File tree
1 file changed
+5
-5
lines changed- rules/cross-platform
1 file changed
+5
-5
lines changedLines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
53 | | - | |
54 | | - | |
55 | | - | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
56 | 56 | | |
57 | 57 | | |
58 | | - | |
| 58 | + | |
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
| |||
0 commit comments