Validate entropy values from flow and alert logs.
match:
event_type: alert
alert.signature_id: 1
+ metadata.entropy.file_data: 4.150007324019584
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 2
+ metadata.entropy.file_data: 4.150007324019584
- filter:
count: 0
match:
match:
event_type: alert
alert.signature_id: 4
+ metadata.entropy.file_data: 4.150007324019584
- filter:
count: 0
match:
match:
event_type: alert
alert.signature_id: 7
+ metadata.entropy.file_data: 4.150007324019584
- filter:
count: 0
match:
match:
event_type: alert
alert.signature_id: 10
+ metadata.entropy.file_data: 4.150007324019584
+ - filter:
+ count: 1
+ match:
+ event_type: flow
+ src_ip: 10.92.95.2
+ dest_ip: 10.92.67.138
+ flow.pkts_toserver: 5
+ flow.pkts_toclient: 5
+ metadata.entropy.file_data: 4.150007324019584