Skip to content

Refine expression for Boot/Kernel Configuration rule#95

Merged
dvas0004 merged 2 commits intomainfrom
EFA006-patch-9
Mar 9, 2026
Merged

Refine expression for Boot/Kernel Configuration rule#95
dvas0004 merged 2 commits intomainfrom
EFA006-patch-9

Conversation

@EFA006
Copy link
Collaborator

@EFA006 EFA006 commented Mar 9, 2026

Replaced file.type with event.category as not all beats are logging file.type.

Additionally some logical issues.

Replaced file.type with event.category as not all beats are logging file.type. 

Additionally some logical issues.
@EFA006 EFA006 requested a review from dvas0004 March 9, 2026 12:12
@EFA006 EFA006 added the Alert Tuning The tuning of alerts label Mar 9, 2026
@dvas0004 dvas0004 merged commit 2eb73d9 into main Mar 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Alert Tuning The tuning of alerts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants