37f28be816
This rule is working as expected, only instances of this alert in telemetry is for testing environments. - uses `iam` instead of `any` for eql query - added highlighted fields