Skip to content

Commit 6108683

Browse files
authored
Add data_stream.namespace to event stats
1 parent f58908f commit 6108683

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,8 @@ from
6262
host.name,
6363
http.request.method,
6464
http.response.status_code,
65-
event.dataset
65+
event.dataset,
66+
data_stream.namespace
6667
6768
| stats
6869
Esql.event_count = count(),
@@ -72,7 +73,8 @@ from
7273
Esql.http_request_method_values = values(http.request.method),
7374
Esql.http_response_status_code_values = values(http.response.status_code),
7475
Esql.url_original_url_decoded_to_lower_values = values(Esql.url_original_url_decoded_to_lower),
75-
Esql.event_dataset_values = values(event.dataset)
76+
Esql.event_dataset_values = values(event.dataset),
77+
Esql.data_stream_namespace_values = values(data_stream.namespace)
7678
by source.ip
7779
'''
7880

0 commit comments

Comments
 (0)