Puppet ran in the last 30 minutes


Description

Puppet ran in the last 30 minutes

Query · wazuh

match="Puppet: OK"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=ossec
  2. match="^ossec: output:"
  3. match="^ossec: output: 'timestamp_puppet"
  4. 80091 Puppet ran in the last 30 minutes suppression level 0 this rule
    match="Puppet: OK"

Rule dependencies

Depends on

Raw source Puppet ran in the last 30 minutes · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="80091" level="0">
        <if_sid>80090</if_sid>
        <match>Puppet: OK</match>
        <description>Puppet ran in the last 30 minutes</description>
    </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.