Skip to content

Commit 1bfb02c

Browse files
committed
Update multiple_alerts_elastic_defend_panw_fortigate_by_host.toml
1 parent 0bea5f8 commit 1bfb02c

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

rules/cross-platform/multiple_alerts_elastic_defend_panw_fortigate_by_host.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,10 +58,10 @@ FROM logs-* metadata _id
5858
Esql.process_executable_values = VALUES(process.executable),
5959
Esql.host_id_values = VALUES(host.id),
6060
Esql.user_name_values = VALUES(user.name),
61-
DD = VALUES(destination.ip)
61+
Esql.destination_ip_values = VALUES(destination.ip)
6262
by Esql.source_ip
6363
| where Esql.event_module_distinct_count >= 2
64-
| keep Esql.alerts_count, Esql.source_ip, Esql.host_id_values, Esql.user_name_values, Esql.event_module_values, Esql.message_values, Esql.process_executable_values
64+
| keep Esql.alerts_count, Esql.source_ip, Esql.destination_ip_values, Esql.host_id_values, Esql.user_name_values, Esql.event_module_values, Esql.message_values, Esql.process_executable_values
6565
'''
6666
note = """## Triage and analysis
6767

0 commit comments

Comments
 (0)