Wazuh API: response code returned error. · http_status_code = 200
Description
Wazuh API: $(endpoint) response code returned error.
Query · wazuh
field http_status_code="200"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=wazuh-api -
field http_status_code="200"
Refined by
9 rules chain off this one, narrowing it further.
Rule dependencies
Depends on
-
composes · Wazuh if_sid
400