NextCloud file deleted.
Description
NextCloud file deleted.
Query · wazuh
match="File deleted:"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=json AND field @source="NextCloud" -
match="File deleted:"
Rule dependencies
Depends on
-
composes · Wazuh if_sid
88200 -
composes · Wazuh if_sid
88201