Skip to content

Commit 9aa9adf

Browse files
add ESQL_priv. to keep
1 parent c594c43 commit 9aa9adf

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/execution_aws_ec2_lolbin_via_ssm.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -221,7 +221,7 @@ FROM logs-aws.cloudtrail*, logs-endpoint.* METADATA _id, _version, _index
221221
Esql.aws_cloudtrail_first_event_ts
222222
) <= 5
223223
| SORT Esql.aws_cloudtrail_first_event_ts ASC
224-
| KEEP Esql.*
224+
| KEEP Esql.*, Esql_priv.*
225225
'''
226226

227227

0 commit comments

Comments
 (0)