Elastic low stable kql
My First Rule
This rule helps you test and practice using alerts with Elastic Security as you get set up. It’s not a sign of threat activity.
Detection Logic
event.kind:event False Positives
- ⚠ This rule is not looking for threat activity. Disable the rule if you're already familiar with alerts.
Field Validations
Loading…
Comments (0)
Loading comments...