Docker: Checkpoint set at container · docker.status = checkpoint
Description
Docker: Checkpoint set at container $(docker.Actor.Attributes.name)
Query · wazuh
field docker.status="^checkpoint$"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field integration="^docker$" -
field docker.status="^checkpoint$"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
87900