[Rule Tuning] adjust duplicate ssh brute force rule names and add unit test (#2321)

* added unit test for duplicate rule names

* adjusted macos file name and updated date values

* removed unit test and added assertion error in rule loader

* addressed flake errors

* addressed flake errors

* Update rules/linux/credential_access_potential_linux_ssh_bruteforce.toml
This commit is contained in:
Terrance DeJesus
2022-09-26 10:04:38 -04:00
committed by GitHub
parent 4366702b34
commit b00de3e445
4 changed files with 12 additions and 4 deletions
@@ -16,7 +16,7 @@ from = "now-9m"
index = ["auditbeat-*", "logs-system.auth-*"]
language = "eql"
license = "Elastic License v2"
name = "Potential SSH Brute Force Detected"
name = "Potential Linux SSH Brute Force Detected"
note = """## Triage and analysis
### Investigating Potential SSH Brute Force Attack