Skip to content

Commit 285cf75

Browse files
Added the from and interval changes that were forgotten
1 parent ce84f54 commit 285cf75

15 files changed

+30
-0
lines changed

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_adversary_behavior_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected an Adversary Behavior. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Adversary Behavior - Detected - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_cred_dumping_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected Credential Dumping. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Credential Dumping - Detected - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_cred_dumping_prevented.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint prevented Credential Dumping. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Credential Dumping - Prevented - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_cred_manipulation_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected Credential Manipulation. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Credential Manipulation - Detected - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_cred_manipulation_prevented.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint prevented Credential Manipulation. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Credential Manipulation - Prevented - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_exploit_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected an Exploit. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Exploit - Detected - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_exploit_prevented.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint prevented an Exploit. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Exploit - Prevented - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_malware_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected Malware. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Malware - Detected - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_malware_prevented.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint prevented Malware. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Malware - Prevented - Elastic Endpoint",

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/elastic_endpoint_security_permission_theft_detected.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
{
22
"description": "Elastic Endpoint detected Permission Theft. Click the Elastic Endpoint icon in the event.module column or the link in the rule.reference column in the External Alerts tab of the SIEM Detections page for additional information.",
3+
"from": "now-660s",
34
"index": [
45
"endgame-*"
56
],
7+
"interval": "10m",
68
"language": "kuery",
79
"max_signals": 100,
810
"name": "Permission Theft - Detected - Elastic Endpoint",

0 commit comments

Comments
 (0)