Skip to content

Commit 1a015e8

Browse files
authored
Update multiple_alerts_from_different_modules_by_srcip.toml
1 parent d87df0f commit 1a015e8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/multiple_alerts_from_different_modules_by_srcip.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ from .alerts-security.*
4646
Esql.rule_severity_values = VALUES(kibana.alert.risk_score) by source.ip
4747
4848
// filter for alerts from same source.ip reported by different integrations with unique categories and with different severity levels
49-
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73)
49+
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73 or Esql.rule_severity_values == 99)
5050
| keep source.ip, Esql.*
5151
'''
5252
note = """## Triage and analysis

0 commit comments

Comments
 (0)