Elastic low stable kql

My First Rule

This rule helps you test and practice using alerts with Elastic Security as you get set up. It’s not a sign of threat activity.

View Source

Detection Logic

event.kind:event

False Positives

  • This rule is not looking for threat activity. Disable the rule if you're already familiar with alerts.

Field Validations

Loading…

Comments (0)

Loading comments...