Syscheck Audit · match ossec: Audit:


Description

Syscheck Audit: $(extra_data)

Query · wazuh

match="^ossec: Audit:"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=ossec
  2. 517 Syscheck Audit · match ossec: Audit: refinement level 7 this rule
    match="^ossec: Audit:"

Rule dependencies

Depends on

Raw source Syscheck Audit · match ossec: Audit: · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="517" level="7">
    <if_sid>500</if_sid>
    <match>^ossec: Audit:</match>
    <description>Syscheck Audit: $(extra_data)</description>
    <group>syscheck,gdpr_II_5.1.f,gdpr_IV_35.7.d,</group>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.