initial patterns

This commit is contained in:
Fabrizio Salmi
2024-12-21 01:04:06 +01:00
parent 1191ba007d
commit 2636affe5b
20 changed files with 80 additions and 0 deletions

View File

@@ -0,0 +1,4 @@
@block_correlation {
path_regexp correlation "(?i)(@eq 0|@ge 5|@eq 0|@ge %{tx.inbound_anomaly_score_threshold}|@ge %{tx.outbound_anomaly_score_threshold}|@lt 2|@ge %{tx.inbound_anomaly_score_threshold}|@ge %{tx.outbound_anomaly_score_threshold}|@lt 3|@gt 0|@lt 4|@lt 1|@lt 1|@lt 2|@lt 2|@lt 3|@lt 3|@lt 4|@lt 4)"
}
respond @block_correlation 403