ECS::LogEntry::Rule
Inherits JSON::Serializable < Struct < Value < Object
Constructors
Instance methods
rule.author
Name, organization, or pseudonym of the author or authors who created the rule used to generate this event.
Level: Extended Type: Keyword Example:
["Star-Lord"]
rule.author
Name, organization, or pseudonym of the author or authors who created the rule used to generate this event.
Level: Extended Type: Keyword Example:
["Star-Lord"]
rule.category
A categorization value keyword used by the entity using the rule for detection of this event.
Level: Extended Type: Keyword Example:
Attempted Information Leak
rule.category
A categorization value keyword used by the entity using the rule for detection of this event.
Level: Extended Type: Keyword Example:
Attempted Information Leak
rule.description
The description of the rule generating the event.
Level: Extended Type: Keyword Example:
Block requests to public DNS over HTTPS / TLS protocols
rule.description
The description of the rule generating the event.
Level: Extended Type: Keyword Example:
Block requests to public DNS over HTTPS / TLS protocols
rule.id
A rule ID that is unique within the scope of an agent, observer, or other entity using the rule for detection of this event.
Level: Extended Type: Keyword Example:
101
rule.id
A rule ID that is unique within the scope of an agent, observer, or other entity using the rule for detection of this event.
Level: Extended Type: Keyword Example:
101
rule.license
Name of the license under which the rule used to generate this event is made available.
Level: Extended Type: Keyword Example:
Apache 2.0
rule.license
Name of the license under which the rule used to generate this event is made available.
Level: Extended Type: Keyword Example:
Apache 2.0
rule.name
The name of the rule or signature generating the event.
Level: Extended Type: Keyword Example:
BLOCK_DNS_over_TLS
rule.name
The name of the rule or signature generating the event.
Level: Extended Type: Keyword Example:
BLOCK_DNS_over_TLS
rule.reference
Reference URL to additional information about the rule used to generate this event.
The URL can point to the vendor's documentation about the rule. If that's not available, it can also be a link to a more general page describing this type of alert.
Level: Extended Type: Keyword Example:
https://en.wikipedia.org/wiki/DNS_over_TLS
rule.reference
Reference URL to additional information about the rule used to generate this event.
The URL can point to the vendor's documentation about the rule. If that's not available, it can also be a link to a more general page describing this type of alert.
Level: Extended Type: Keyword Example:
https://en.wikipedia.org/wiki/DNS_over_TLS
rule.ruleset
Name of the ruleset, policy, group, or parent category in which the rule used to generate this event is a member.
Level: Extended Type: Keyword Example:
Standard_Protocol_Filters
rule.ruleset
Name of the ruleset, policy, group, or parent category in which the rule used to generate this event is a member.
Level: Extended Type: Keyword Example:
Standard_Protocol_Filters
rule.uuid
A rule ID that is unique within the scope of a set or group of agents, observers, or other entities using the rule for detection of this event.
Level: Extended Type: Keyword Example:
1100110011
rule.uuid
A rule ID that is unique within the scope of a set or group of agents, observers, or other entities using the rule for detection of this event.
Level: Extended Type: Keyword Example:
1100110011
rule.version
The version / revision of the rule being used for analysis.
Level: Extended Type: Keyword Example:
1.1
rule.version
The version / revision of the rule being used for analysis.
Level: Extended Type: Keyword Example:
1.1