Login: A user logged into the system.
Description
Login: A user logged into the system.
Query · wazuh
field fw_action="Login"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=checkpoint-smart1 -
field fw_action="Login"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
64220