Skip to content

Commit d87df0f

Browse files
authored
Update multiple_alerts_from_different_modules_by_dstip.toml
1 parent 91a8cc8 commit d87df0f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ from .alerts-security.*
4545
Esql.rule_severity_values = VALUES(kibana.alert.risk_score) by destination.ip
4646
4747
// filter for alerts from same destination.ip reported by different integrations with unique categories and with different severity levels or presence of high severity alerts
48-
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73)
48+
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73 or Esql.rule_severity_values == 99)
4949
| keep destination.ip, Esql.*
5050
'''
5151
note = """## Triage and analysis

0 commit comments

Comments
 (0)