Skip to content

Commit 63b3ca2

Browse files
authored
Update multiple_alerts_from_different_modules_by_dstip.toml
1 parent 295031d commit 63b3ca2

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,9 @@ updated_date = "2025/12/15"
66
[rule]
77
author = ["Elastic"]
88
description = """
9-
This rule uses alert data to determine when multiple alerts from different integrations with unique event categories and
10-
involving the same destination.ip are triggered. Analysts can use this to prioritize triage and response, as these IP address
11-
is more likely to be related to a compromise.
9+
This rule uses alert data to determine when multiple alerts from different integrations with unique event categories and involving
10+
the same destination.ip are triggered. Analysts can use this to prioritize triage and response, as these IP address is more likely
11+
to be related to a compromise.
1212
"""
1313
from = "now-60m"
1414
interval = "30m"

0 commit comments

Comments
 (0)