Wazuh API: response code returned error. · http_status_code = 200


Description

Wazuh API: $(endpoint) response code returned error.

Query · wazuh

field http_status_code="200"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=wazuh-api
  2. 405 Wazuh API: response code returned error. · http_status_code = 200 anchor level 7 this rule
    field http_status_code="200"

Rule dependencies

Depends on

Raw source Wazuh API: response code returned error. · http_status_code = 200 · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="405" level="7">
    <if_sid>400</if_sid>
    <field name="http_status_code" negate="yes">200</field>
    <description>Wazuh API: $(endpoint) response code returned error.</description>
    <group>gpg13_4.3</group>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.