You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Be good to get more rules like this working with cisco asa and checkpoint firewall index patterns. Will need alert suppression to prevent the siem being flooded.
Link to Rule
https://www.elastic.co/guide/en/security/current/rpc-remote-procedure-call-to-the-internet.html
Rule Tuning Type
Data Quality - Ensuring integrity and quality of data used by detection rules.
Description
Currently, the Rule will only work with Network Packet Capture and Palo Alto Next-Gen Firewall.
It would be kind if we could have the ability to apply this and similar rules to logs collected by Fortinet FortiGate Firewall Logs as well.
The following rules there identified in issue #3998 that may be possible to trigger by different vendor Firewalls as well:
Example Data
No response
The text was updated successfully, but these errors were encountered: