Skip to content

Commit fd8c8bd

Browse files
authored
Add data_stream.namespace to event statistics
1 parent a82c3e2 commit fd8c8bd

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,7 +110,8 @@ from
110110
host.name,
111111
http.request.method,
112112
http.response.status_code,
113-
event.dataset
113+
event.dataset,
114+
data_stream.namespace
114115
115116
| stats
116117
Esql.event_count = count(),
@@ -120,7 +121,8 @@ from
120121
Esql.http_request_method_values = values(http.request.method),
121122
Esql.http_response_status_code_values = values(http.response.status_code),
122123
Esql.url_original_url_decoded_to_lower_values = values(Esql.url_original_url_decoded_to_lower),
123-
Esql.event_dataset_values = values(event.dataset)
124+
Esql.event_dataset_values = values(event.dataset),
125+
Esql.data_stream_namespace_values = values(data_stream.namespace)
124126
by source.ip
125127
'''
126128

0 commit comments

Comments
 (0)