Skip to content

Commit 63facf9

Browse files
committed
updating detection
1 parent a7425f0 commit 63facf9

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

detections/application/cisco_ai_defense_security_alerts.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ drilldown_searches:
5050
earliest_offset: $info_min_time$
5151
latest_offset: $info_max_time$
5252
rba:
53-
message: Cisco AI Defense Security Alert has been detected for the application id - [$application_id$]
53+
message: Cisco AI Defense Security Alert has been detected for the application name - [$application_name$]
5454
risk_objects:
5555
- field: application_id
5656
type: other
@@ -70,5 +70,4 @@ tests:
7070
attack_data:
7171
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/cisco_ai_defense_alerts/cisco_ai_defense.log
7272
source: cisco_ai_defense
73-
sourcetype: cisco:ai:defense
74-
73+
sourcetype: cisco:ai:defense

0 commit comments

Comments
 (0)