Skip to content

Commit 6f3396f

Browse files
authored
Merge branch 'develop' into auto-ta-update-271
2 parents e6d4910 + 7cd1729 commit 6f3396f

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ search: |
2424
| bin _time span=1d
2525
| stats count AS Total_Alerts, dc(signature_id) AS sig_count, values(signature_id) AS signature_id, values(category) AS category, values(message) AS message, values(snort_rule_groups) AS snort_rule_groups, values(connection_id) AS connection_id, values(rule) AS rule, values(dest_port) AS dest_port, values(transport) AS transport, values(app) AS app, values(signature) AS signature, values(src_ip) AS src_ip BY _time dest_ip threat
2626
| lookup threat_snort_count threat OUTPUT description, distinct_count_snort_ids
27-
| table _time, dest_ip, threat, category, message, description, signature_id, signature, snort_rule_groups, sig_count, distinct_count_snort_ids, connection_id, rule, dest_port, transport, app
27+
| table _time, dest_ip, src_ip, threat, category, message, description, signature_id, signature, snort_rule_groups, sig_count, distinct_count_snort_ids, connection_id, rule, dest_port, transport, app
2828
| where sig_count >= distinct_count_snort_ids
2929
| `cisco_secure_firewall___intrusion_events_by_threat_activity_filter`
3030
how_to_implement: |
@@ -53,7 +53,7 @@ drilldown_searches:
5353
earliest_offset: $info_min_time$
5454
latest_offset: $info_max_time$
5555
rba:
56-
message: Potential $threat$ activity detected from $src_ip$ to $dest_ip$.
56+
message: Potential $threat$ activity detected on $dest_ip$ originating from $src_ip$.
5757
risk_objects:
5858
- field: dest_ip
5959
type: system

0 commit comments

Comments
 (0)