644d2f5b26
* [New Rule] New Systemd Timer Created * improve query runtime performance * added process.name entries for alert reduction * attempt to fix gh unit testing failure * added host.os.type==linux to fix unit test error * Added OSQuery to investigation guides * added additional process names * removed investigation guides to add in future PR * removed investigation guide tag * Changed rule to new_terms rule to reduce FPs * fixed query * formatting fix * Learnt another thing about KQL.. Formatting fix. * unit test fix * Update rules/linux/persistence_systemd_scheduled_timer_created.toml Co-authored-by: eric-forte-elastic <119343520+eric-forte-elastic@users.noreply.github.com> --------- Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com> Co-authored-by: eric-forte-elastic <119343520+eric-forte-elastic@users.noreply.github.com>