f2d8ab54d7
This rule is performing well in telemetry, low volume and expected alerts. No major changes to rule query. - reduced execution window - updated description and IG - added highlighted fields Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>