Pre-match rule for kernel messages.
Description
Pre-match rule for kernel messages.
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
Matches no fields of its own.
Refined by
22 rules chain off this one, narrowing it further.
Rule logic
Matches no fields of its own — an anchor that 22 rules refine. Deploying it alone raises nothing.
Source file