capitalized titles
corrected capitalization of titles and removed literals from config
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
title: AWS EC2 VM Export failure
|
||||
title: AWS EC2 VM Export Failure
|
||||
id: 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
|
||||
status: experimental
|
||||
description: An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
title: Elastic Common Schema and Elastic Exported Fields mapping for AWS CloudTrail logs
|
||||
title: Elastic Common Schema And Elastic Exported Fields Mapping For AWS CloudTrail Logs
|
||||
order: 20
|
||||
backends:
|
||||
- es-qs
|
||||
@@ -54,15 +54,6 @@ overrides:
|
||||
- (\(\(event.action:\"ConsoleLogin\".* aws.cloudtrail.error_code.keyword:\*\)\))
|
||||
- (\(\(aws.cloudtrail.response_elements.keyword:\*Failure\*.* aws.cloudtrail.error_message.keyword:\*\)\))
|
||||
- (\(\(aws.cloudtrail.response_elements.keyword:\*Failure\*.* aws.cloudtrail.error_code.keyword:\*\)\))
|
||||
literals:
|
||||
- ((aws.cloudtrail.error_message.keyword:* OR aws.cloudtrail.error_code.keyword:*) OR (event.action:"ConsoleLogin" AND aws.cloudtrail.response_elements.keyword:*Failure*))
|
||||
- ((aws.cloudtrail.error_code.keyword:* OR aws.cloudtrail.error_message.keyword:*) OR (event.action:"ConsoleLogin" AND aws.cloudtrail.response_elements.keyword:*Failure*))
|
||||
- ((aws.cloudtrail.error_message.keyword:* OR aws.cloudtrail.error_code.keyword:*) OR (aws.cloudtrail.response_elements.keyword:*Failure* AND event.action:"ConsoleLogin"))
|
||||
- ((aws.cloudtrail.error_code.keyword:* OR aws.cloudtrail.error_message.keyword:*) OR (aws.cloudtrail.response_elements.keyword:*Failure* AND event.action:"ConsoleLogin"))
|
||||
- ((event.action:"ConsoleLogin" AND aws.cloudtrail.response_elements.keyword:*Failure*) OR (aws.cloudtrail.error_message.keyword:* OR aws.cloudtrail.error_code.keyword:*))
|
||||
- ((event.action:"ConsoleLogin" AND aws.cloudtrail.response_elements.keyword:*Failure*) OR (aws.cloudtrail.error_code.keyword:* OR aws.cloudtrail.error_message.keyword:*))
|
||||
- ((aws.cloudtrail.response_elements.keyword:*Failure* AND event.action:"ConsoleLogin") OR (aws.cloudtrail.error_message.keyword:* OR aws.cloudtrail.error_code.keyword:*))
|
||||
- ((aws.cloudtrail.response_elements.keyword:*Failure* AND event.action:"ConsoleLogin") OR (aws.cloudtrail.error_code.keyword:* OR aws.cloudtrail.error_message.keyword:*))
|
||||
- field: event.outcome
|
||||
value: success
|
||||
literals:
|
||||
|
||||
Reference in New Issue
Block a user