MongoDB: End connection


Description

MongoDB: End connection

Query · wazuh

field mongodb.component="NETWORK" AND match="end connection"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. 85750 MongoDB messages anchor level 0
    decoded_as=mongodb
  2. field mongodb.severity="I"
  3. 85757 MongoDB: End connection refinement level 3 this rule
    field mongodb.component="NETWORK" AND match="end connection"

Rule dependencies

Depends on

Raw source MongoDB: End connection · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="85757" level="3">
        <if_sid>85755</if_sid>
        <field name="mongodb.component">NETWORK</field>
        <match>end connection</match>
        <description>MongoDB: End connection</description>
        <group />
    </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.