Skip to content

Commit 5ff1dee

Browse files
committed
Update windows_cisco_secure_endpoint_related_service_stopped.yml
1 parent 58a6e70 commit 5ff1dee

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

detections/endpoint/windows_cisco_secure_endpoint_related_service_stopped.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Windows Cisco Secure Endpoint Related Service Stopped
22
id: df74f45f-01c8-4fd6-bcb8-f6a9ea58307a
3-
version: 7
3+
version: 1
44
date: '2024-12-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
@@ -31,13 +31,13 @@ drilldown_searches:
3131
earliest_offset: $info_min_time$
3232
latest_offset: $info_max_time$
3333
rba:
34-
message: Cisco Secure Endpoint Service $param1$ stopped on $dest$
34+
message: Cisco Secure Endpoint Service $display_name$ stopped on $dest$
3535
risk_objects:
3636
- field: dest
3737
type: system
3838
score: 60
3939
threat_objects:
40-
- field: param1
40+
- field: display_name
4141
type: service
4242
tags:
4343
analytic_story:

0 commit comments

Comments
 (0)