PHP Fatal error.
Description
PHP Fatal error.
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=nginx-errorlog -
regex="^\S+ \S+ [error]" -
match="PHP Fatal error:" -
Matches no fields of its own.
Refined by
1 rule chains off this one, narrowing it further.
Rule dependencies
Depends on
-
composes · Wazuh if_sid
31402 -
composes · Wazuh if_sid
31405
Rule logic
Matches no fields of its own — an anchor that 1 rule refines. Deploying it alone raises nothing.
Source file