My First Rule

edit

This rule helps you test and practice using alerts with Elastic Security as you get set up. It’s not a sign of threat activity.

Rule type: threshold

Rule indices:

  • auditbeat-*
  • filebeat-*
  • logs-*
  • winlogbeat-*

Severity: low

Risk score: 21

Runs every: 24h

Searches indices from: now-30m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 1

References:

Tags:

  • Use Case: Guided Onboarding

Version: 3

Rule authors:

  • Elastic

Rule license: Elastic License v2

Investigation guide

edit

This is a test alert.

This alert does not show threat activity. Elastic created this alert to help you understand how alerts work.

For normal rules, the Investigation Guide will help analysts investigate alerts.

This alert will show once every 24 hours for each host. It is safe to disable this rule.

Rule query

edit
event.kind:event