The specified RR Set does not exist, and should with source IP from , severity . · gcp.jsonPayload.responseCode = NXRRSET
Description
The specified RR Set does not exist, and should with source IP $(gcp.jsonPayload.sourceIP) from $(gcp.resource.labels.location), severity $(gcp.severity).
Query · wazuh
field gcp.jsonPayload.responseCode="^NXRRSET$"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field integration="gcp" -
field gcp.resource.type="^dns_query$" -
field gcp.resource.labels.source_type="^internet$" -
65026The specified RR Set does not exist, and should with source IP from , severity . · gcp.jsonPayload.responseCode = NXRRSET refinement level 10 this rulefield gcp.jsonPayload.responseCode="^NXRRSET$"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
65002 -
composes · Wazuh if_sid
65003