query Zap_u($object) from U {
object == $object
}
query Zap_m($object) from M {
object == $object
}
event A:
key:
event_src.host
filter {
exec_query ( "Zap_u", [$object])!=null
}
event B:
key:
event_src.host
filter {
object.name == "NCR"
}
rule Error:(A -> B) within 1m
on A {
$event_src.host = event_src.host
}
on B {
$event_src.host = event_src.host
}
emit {
$correlation_name = "Predskazano_navodnenie"
$correlation_type = "incident"
$category.generic = "Information Management"
$category.high = "Information Leak"
$category.low = "Critical Information"
$id = "Predskazano_navodnenie"
$importance = "high"