Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add explanation on Rules Syntax documentation which fields can('t) be used #5981

Open
zbalkan opened this issue Mar 22, 2023 · 0 comments
Open

Comments

@zbalkan
Copy link
Contributor

zbalkan commented Mar 22, 2023

On Wazuh Rule Syntax documentation, the section does not mention which fields can be utilized or not.

We know that:

  • agent.* properties are not usable for the <field> in rules.
  • dstuser, srcip are not usable as they are static values.
  • full_log is not usable, even though it is possible to write a rule without getting a syntax warning.

There are probably others too because they are generated on runtime as a part of enrichment and probably appears after rule check. Internals might change but this is important for users to write rules that work.

@zbalkan zbalkan changed the title Add explanation on Rules Syntax documentationwhich fields can('t) be used Add explanation on Rules Syntax documentation which fields can('t) be used Mar 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant