88e0b14709
* [Tuning] Extract dynamic field with 1 value to ECS fields for alerts exclusion Extract dynamic field with 1 value to ECS fields for alerts exclusion: Esql.host_id_values -> host.is Esql.agent_id_values -> agent.id Esql.host_name_values -> host.name * Update multiple_alerts_by_host_ip_and_source_ip.toml * Update newly_observed_elastic_defend_alert.toml * Update defense_evasion_base64_decoding_activity.toml * Update discovery_subnet_scanning_activity_from_compromised_host.toml * Update persistence_web_server_sus_command_execution.toml * Update persistence_web_server_sus_child_spawned.toml * Update rules/cross-platform/multiple_alerts_elastic_defend_netsecurity_by_host.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/linux/impact_potential_bruteforce_malware_infection.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/linux/command_and_control_frequent_egress_netcon_from_sus_executable.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_elastic_defend_netsecurity_by_host.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/newly_observed_elastic_defend_alert.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/newly_observed_elastic_detection_rule.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/windows/credential_access_rare_webdav_destination.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update credential_access_rare_webdav_destination.toml --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>