Elastic critical stable kql
Newly Observed High Severity Suricata Alert
This rule detects Suricata high severity alerts that are observed for the first time in the previous 5 days of alert history. Analysts can use this to prioritize triage and response.
Detection Logic
FROM logs-suricata.*
// high severity alerts
| where event.module == "suricata" and event.kind == "signal" and event.severity == 1 and
rule.name is not null and
not rule.name like "SURICATA STREAM*"
| STATS Esql.alerts_count = count(*),
Esql.first_time_seen = MIN(@timestamp),
Esql.distinct_count_src_ip = COUNT_DISTINCT(source.ip),
Esql.distinct_count_dst_ip = COUNT_DISTINCT(destination.ip),
src_ip_values = VALUES(source.ip),
dst_ip_values = VALUES(destination.ip),
url_dom = VALUES(url.domain),
url_path = VALUES(url.path) by rule.name, event.type
| eval Esql.recent = DATE_DIFF("minute", Esql.first_time_seen, now())
// first time seen is within 10m of the rule execution time
| where Esql.recent <= 10 and
// exclude high volume alerts such as vuln-scanners
Esql.alerts_count <= 5 and Esql.distinct_count_src_ip <= 2 and Esql.distinct_count_dst_ip <= 2
// move dynamic fields to ECS quivalent for rule exceptions
| eval source.ip = MV_FIRST(src_ip_values),
destination.ip = MV_FIRST(dst_ip_values),
url.domain = MV_FIRST(url_dom),
url.path = MV_FIRST(url_path)
| keep rule.name, event.type, Esql.*, source.ip, destination.ip, url.domain, url.path Field Validations
Loading…
Comments (0)
Loading comments...