osquery: query result · osquery.pack = hardware-monitoring
Description
osquery: $(osquery.pack) query result
Query · wazuh
field osquery.pack="^hardware-monitoring$"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
location=osquery$ -
decoded_as=json -
field osquery.pack="^hardware-monitoring$"
Refined by
16 rules chain off this one, narrowing it further.
- osquery: : ACPI table size is · osquery.name = acpi_tables
- osquery: : CPU feature and value · osquery.name = cpuid
- osquery: : ACPI table size is · osquery.name = smbios_tables
- osquery: : NVRAM variable value · osquery.name = nvram
- osquery: : PCI device with vendor is active · osquery.name = pci_devices
Rule dependencies
Depends on
-
composes · Wazuh if_sid
24010