Skip to content

Commit 36d85e8

Browse files
committed
Update multiple_alerts_elastic_defend_panw_fortigate_by_host.toml
1 parent 5a75c4f commit 36d85e8

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

rules/cross-platform/multiple_alerts_elastic_defend_panw_fortigate_by_host.toml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,11 +88,10 @@ FROM logs-* metadata _id
8888
Esql.event_action_values = VALUES(event.action),
8989
Esql.process_executable_values = VALUES(process.executable),
9090
Esql.host_id_values = VALUES(host.id),
91-
Esql.user_name_values = VALUES(user.name),
92-
Esql.destination_ip_values = VALUES(destination.ip)
91+
Esql.user_name_values = VALUES(user.name)
9392
by Esql.source_ip
9493
| where Esql.event_module_distinct_count >= 2
95-
| keep Esql.alerts_count, Esql.source_ip, Esql.destination_ip_values, Esql.host_id_values, Esql.user_name_values, Esql.event_module_values, Esql.message_values, Esql.process_executable_values
94+
| keep Esql.alerts_count, Esql.source_ip, Esql.host_id_values, Esql.user_name_values, Esql.event_module_values, Esql.message_values, Esql.process_executable_values
9695
ource_ip, Esql.destination_ip_values, Esql.host_id_values, Esql.user_name_values, Esql.event_module_values, Esql.message_values, Esql.process_executable_values
9796
'''
9897
note = """## Triage and analysis

0 commit comments

Comments
 (0)