- Notifications
You must be signed in to change notification settings - Fork 603
Labels
Rule: Tuningtweaking or tuning an existing ruletweaking or tuning an existing ruleTeam: TRADEcommunity
Description
Link to Rule
Rule Tuning Type
Data Quality - Ensuring integrity and quality of data used by detection rules.
Description
This rule specifically only looks at indexes that match "logs-o365.audit-default*"
So that this can be used when folks are saving logs to different namespaces, this should be changed to
query = ''' from logs-o365.audit-*
Example Data
No response
Metadata
Metadata
Assignees
Labels
Rule: Tuningtweaking or tuning an existing ruletweaking or tuning an existing ruleTeam: TRADEcommunity