Skip to content

Commit fcd07c7

Browse files
authored
Update multiple_alerts_from_different_modules_by_user.toml
1 parent 1a015e8 commit fcd07c7

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ from .alerts-security.*
4747
Esql.rule_severity_values = VALUES(kibana.alert.risk_score) by user.name, user.id
4848
4949
// filter for alerts from same destination.ip reported by different integrations with unique categories and with different severity levels
50-
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73)
50+
| where Esql.event_module_distinct_count >= 2 and Esql.event_category_distinct_count >= 2 and (Esql.rule_risk_score_distinct_count >= 2 or Esql.rule_severity_values == 73 or Esql.rule_severity_values == 99)
5151
| keep user.name, Esql.*
5252
'''
5353
note = """## Triage and analysis

0 commit comments

Comments
 (0)