[Rule Tuning] adjust duplicate ssh brute force rule names and add unit test (#2321)
* added unit test for duplicate rule names * adjusted macos file name and updated date values * removed unit test and added assertion error in rule loader * addressed flake errors * addressed flake errors * Update rules/linux/credential_access_potential_linux_ssh_bruteforce.toml
This commit is contained in:
@@ -16,7 +16,7 @@ from = "now-9m"
|
||||
index = ["auditbeat-*", "logs-system.auth-*"]
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential SSH Brute Force Detected"
|
||||
name = "Potential Linux SSH Brute Force Detected"
|
||||
note = """## Triage and analysis
|
||||
|
||||
### Investigating Potential SSH Brute Force Attack
|
||||
|
||||
Reference in New Issue
Block a user