Skip to content

Commit cb2fd75

Browse files
authored
Update reconnaissance_web_server_unusual_user_agents.toml
1 parent 38c8583 commit cb2fd75

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

rules/cross-platform/reconnaissance_web_server_unusual_user_agents.toml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -72,14 +72,13 @@ from
7272
@timestamp,
7373
event.dataset,
7474
user_agent.original,
75-
url.path,
7675
source.ip,
7776
agent.id,
7877
host.name,
7978
Esql_url_lower
8079
| stats
8180
Esql.event_count = count(),
82-
Esql.url_path_count_distinct = count_distinct(url.path),
81+
Esql.url_path_count_distinct = count_distinct(Esql_url_lower),
8382
Esql.host_name_values = values(host.name),
8483
Esql.agent_id_values = values(agent.id),
8584
Esql.url_path_values = values(Esql_url_lower),

0 commit comments

Comments
 (0)