Skip to content

Commit

Permalink
updates prebuilt endpoint rules look back time (elastic#1040)
Browse files Browse the repository at this point in the history
  • Loading branch information
benskelker authored and Ben Skelker committed May 7, 2020
1 parent 4cce20b commit ef3b7eb
Show file tree
Hide file tree
Showing 15 changed files with 15 additions and 15 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ External Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Alerts tab of the SIEM *Detections* page for additional information.

*Runs every*: 10 minutes

*Searches indices from*: now-660s ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)
*Searches indices from*: now-15m ({ref}/common-options.html#date-math[Date Math format], see also <<rule-schedule, `Additional look-back time`>>)

*Maximum signals per execution*: 100

Expand Down

0 comments on commit ef3b7eb

Please sign in to comment.