Traffic Dropped: from to · sophos_fw_status_msg = Drop
Description
Traffic Dropped: from $(src_ip) to $(dst_ip)
Query · wazuh
field sophos_fw_status_msg="Drop"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=sophos-fw -
field sophos_fw_status_msg="Drop"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
70020