Update lnx_susp_named.yml

This commit is contained in:
yugoslavskiy
2020-11-29 21:31:54 +01:00
committed by GitHub
parent 769ef23ccf
commit 871f965109
+4 -4
View File
@@ -10,10 +10,10 @@ logsource:
product: linux
service: syslog
detection:
keywords|contains:
- ' dropping source port zero packet from '
- ' denied AXFR from '
- ' exiting (due to fatal error)'
keywords:
- '* dropping source port zero packet from *'
- '* denied AXFR from *'
- '* exiting (due to fatal error)*'
condition: keywords
falsepositives:
- Unknown