diff --git a/appendix_meta_rules.md b/appendix_meta_rules.md index b3b4225..ab9c9b4 100644 --- a/appendix_meta_rules.md +++ b/appendix_meta_rules.md @@ -346,7 +346,7 @@ Simple example : More than or equal 100 failed login attempts to a destination h title: Many failed logins id: 0e95725d-7320-415d-80f7-004da920fc11 correlation: -type: event_count + type: event_count rules: - 5638f7c0-ac70-491d-8465-2a65075e0d86 group-by: @@ -676,4 +676,5 @@ detection: EventID: - 528 - 4624 -``` \ No newline at end of file + condition: selection +```