Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi team,
The purpose of this PR is to update the
ConfigHistory
rules. The rule 80453 can flood the Wazuh if the AWS Config is enabled. For this reason, I have silent this rule when theaws.configurationItemStatus
field has the valueOK
. And created 4 new child rules that will be triggered once the specific status appears.The valid values for
aws.configurationItemStatus
are:OK
– The resource configuration has been updatedResourceDiscovered
– The resource was newly discoveredResourceNotRecorded
– The resource was discovered but its configuration was not recorded since the recorder excludes the recording of resources of this typeResourceDeleted
– The resource was deletedResourceDeletedNotRecorded
– The resource was deleted but its configuration was not recorded since the recorder excludes the recording of resources of this typeAs I have mentioned above when it is
OK
the rule will be silenced (level = 0) for the rest I have set the level to 3 as of now.Kind regards,
Bin.