Skip to content

Commit 4fcaef3

Browse files
vikman90jesuslinares
authored andcommitted
Change agent event queue status field for level, and rule description
1 parent f49ee45 commit 4fcaef3

File tree

2 files changed

+10
-10
lines changed

2 files changed

+10
-10
lines changed

decoders/0005-wazuh_decoders.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,5 +12,5 @@
1212
<parent>wazuh</parent>
1313
<prematch offset="after_parent">^Agent buffer:</prematch>
1414
<regex offset="after_prematch">^ '(\S+)'.</regex>
15-
<order>status</order>
15+
<order>level</order>
1616
</decoder>

rules/0016-wazuh_rules.xml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -14,35 +14,35 @@
1414
<rule id="201" level="0">
1515
<if_sid>200</if_sid>
1616
<match>^wazuh: Agent buffer: </match>
17-
<description>Agent buffer rule</description>
17+
<description>Agent event queue rule</description>
1818
<group>agent_flooding,</group>
1919
</rule>
2020

2121
<rule id="202" level="7">
2222
<if_sid>201</if_sid>
23-
<status>%</status>
24-
<description>Agent buffer is close to an overflow state.</description>
23+
<field name="level">%</field>
24+
<description>Agent event queue is $(level) full.</description>
2525
<group>agent_flooding,</group>
2626
</rule>
2727

2828
<rule id="203" level="9">
2929
<if_sid>201</if_sid>
30-
<status>full</status>
31-
<description>Agent buffer is full. Events may be lost.</description>
30+
<field name="level">full</field>
31+
<description>Agent event queue is full. Events may be lost.</description>
3232
<group>agent_flooding,</group>
3333
</rule>
3434

3535
<rule id="204" level="12">
3636
<if_sid>201</if_sid>
37-
<status>flooded</status>
38-
<description>Agent buffer is flooded. Check the agent configuration.</description>
37+
<field name="level">flooded</field>
38+
<description>Agent event queue is flooded. Check the agent configuration.</description>
3939
<group>agent_flooding,</group>
4040
</rule>
4141

4242
<rule id="205" level="3">
4343
<if_sid>201</if_sid>
44-
<status>normal</status>
45-
<description>Agent buffer is back to normal load.</description>
44+
<field name="level">normal</field>
45+
<description>Agent event queue is back to normal load.</description>
4646
<group>agent_flooding,</group>
4747
</rule>
4848
</group>

0 commit comments

Comments
 (0)