Skip to content

Commit b3a4ab3

Browse files
Samirbousw0rk3r
andauthored
Update rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml
Co-authored-by: Jonhnathan <[email protected]>
1 parent 8371587 commit b3a4ab3

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ This detection correlates Palo Alto Networks (PANW) command and control events w
1111
the source process performing the network activity.
1212
"""
1313
from = "now-9m"
14-
index = ["logs-endpoint.events.network-default*", "logs-panw.panos-default-*"]
14+
index = ["logs-endpoint.events.network-*", "logs-panw.panos-*"]
1515
language = "eql"
1616
license = "Elastic License v2"
1717
name = "PANW Command and Control Correlation"

0 commit comments

Comments
 (0)