FreeIPA (apache format)


Description

FreeIPA (apache format)

Query · wazuh

match="] ipa:"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=apache-errorlog
  2. match="^[error]"
  3. 82201 FreeIPA (apache format) anchor level 0 this rule
    match="] ipa:"

Refined by

1 rule chains off this one, narrowing it further.

Rule dependencies

Depends on

Raw source FreeIPA (apache format) · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="82201" level="0">
        <if_sid>30101</if_sid>
        <match>] ipa:</match>
        <description>FreeIPA (apache format)</description>
    </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.