|
@@ -4,6 +4,7 @@ name: test/simple-trigger
|
|
|
data:
|
|
|
- source_url: https://invalid.com/test.list
|
|
|
dest_file: ./simple_patterns.txt
|
|
|
+ type: string
|
|
|
description: "Simple trigger with external data"
|
|
|
filter: "evt.Line.Labels.type =='testlog' && evt.Parsed.tainted_data in File('./simple_patterns.txt')"
|
|
|
groupby: evt.Meta.source_ip
|