Link Search Menu Expand Document

Hostname_Bandwidth_Exceeds_Threshold_2

ID: 100240

Description:

A (d_asset) hostname has used more than 1GB in the last 12 hours

Repository: Group: Network Type: metaflow

Default Status:

Disabled

Tags:
Network
 

Selector:

Query:

sip:192.168.50.* OR dip:192.168.50.*

Filters:

Field MUST hit
   
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
d_asset.hostname asset application activity

Risks:

Risks Base Score Dimension
     

Attributes:

Alias Key
TotalBytes totalB
Device meta.device
SourceIP sip
TransBytes txB
RecvBytes rxB
Hostname d_asset.hostname

Correlation Rules:

Aggregation:

Name Window Field AggType Match
ThresholdExceeded 12 hours totalB sum gt 1e+09
  Risks: BANDWIDTH_ANOMALY    

History:

User Date
ho*d@fluencysecurity.com 2021 Apr 20 15:47:25 EDT

This page was automatically created/formatted on Tue, 2021 Oct 19 00:29:17 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)