Predefined Alert Rules

Overview

Every Energy Logserver integration package ships a set of predefined alert rules that detect common threats and operational problems for the data source it handles. When you install an integration, its installer imports these rules into the Alert Rules List, so you do not have to write detection logic from scratch.

This chapter catalogues those rules. For how alerting works and how to build your own, see Alerting System.

Where the rules come from

Access: ELS Console → SIEM → Integrations → (select an integration)Advanced → Step 3 Alerts

The Advanced wizard lists the rules bundled with an integration before you install them. After installation they appear in SIEM → Alerts → Alert Rules List, grouped by the value in each rule’s Group Name. This catalogue uses the same grouping.

Two classes of rule

The rules split into two kinds, and the difference matters when you plan detection:

  • Static rules install exactly as written: a fixed query against a fixed index pattern. Behaviour is identical on every deployment. These are catalogued below by group.

  • Adaptive rules (Empowered AI) use a machine-learning model trained on your own data. The rule definition is fixed, but the anomaly threshold is specific to your environment, so behaviour is not identical across installations. These are listed in their own section.

Reading the tables

Each static table lists the rules in one group:

  • Alert rule: the name as it appears in the Alert Rules List.

  • Type: the detection method (frequency, any, flatline, spike, cardinality, new_term, metric_aggregation).

  • Index pattern: the indices the rule queries.

All predefined rules install disabled. Review each rule, adjust its filters and notification method for your environment, then enable it. The default importance is 100 unless a rule states otherwise.

Note

This catalogue reflects the integration packages that ship their rule definitions in the Energy Logserver integrations repository. Rules are versioned with their package, so names and counts can change between releases. See Coverage for what is included and what is not.

Static alert rules by group

151 static rules across 9 groups. Each installs exactly as listed; adjust filters and notification method for your environment, then enable it.

Microsoft Windows

36 rules, from beats.

Alert rule

Type

Index pattern

Windows - Account lock

any

windows-winlogbeat-*

Windows - Admin night logon

any

windows-winlogbeat-*

Windows - Admin task as user

any

windows-winlogbeat-*

Windows - Application error

any

windows-winlogbeat-*

Windows - Application hang

any

windows-winlogbeat-*

Windows - Audit policy changed

any

windows-winlogbeat-*

Windows - Code integrity changed

any

windows-winlogbeat-*

Windows - Diff IPs logon

cardinality

windows-winlogbeat-*

Windows - Driver loaded

any

windows-winlogbeat-*

Windows - Event service error

any

windows-winlogbeat-*

Windows - Eventlog service stopped

any

windows-winlogbeat-*

Windows - file insufficient privileges

frequency

windows-winlogbeat-*

Windows - Firewall rule add

any

windows-winlogbeat-*

Windows - Firewall rule deleted

any

windows-winlogbeat-*

Windows - Firewall rule modified

any

windows-winlogbeat-*

Windows - Kerberos pre-authentication failed

any

windows-winlogbeat-*

Windows - Login with explicit credentials

any

windows-winlogbeat-*

Windows - Logs deleted

any

windows-winlogbeat-*

Windows - Member added to a security-enabled global group

any

windows-winlogbeat-*

Windows - Member added to a security-enabled local group

any

windows-winlogbeat-*

Windows - Member added to a security-enabled universal group

any

windows-winlogbeat-*

Windows - New device

any

windows-winlogbeat-*

Windows - New service installed

any

windows-winlogbeat-*

Windows - No Logs

flatline

windows-winlogbeat-*

Windows - Package installation

any

windows-winlogbeat-*

Windows - Password policy change

any

windows-winlogbeat-*

Windows - Reset password attempt

any

windows-winlogbeat-*

Windows - Security local group was changed

any

windows-winlogbeat-*

Windows - Security log full

any

windows-winlogbeat-*

Windows - Start up

any

windows-winlogbeat-*

Windows - SUNBURST Fingerprint

any

windows-winlogbeat-*

Windows - System has been shutdown

any

windows-winlogbeat-*

Windows - The system time was changed

any

windows-winlogbeat-*

Windows TaskScheduler - Task created

any

windows-winlogbeat-*

Windows TaskScheduler - Task deleted

any

windows-winlogbeat-*

Windows TaskScheduler - Task executed

any

windows-winlogbeat-*

Microsoft Windows Security

31 rules, from beats.

Alert rule

Type

Index pattern

Windows Security - Connection initiated via certutil_exe

any

windows-winlogbeat-*

Windows Security - Detect outbound rdp connections over non standard tools

any

windows-winlogbeat-*

Windows Security - Detect RDP file creation from suspicious application

any

windows-winlogbeat-*

Windows Security - Detect rootkit Moriya

any

windows-winlogbeat-*

Windows Security - Detection of relevant antivirus events

any

windows-winlogbeat-*

Windows Security - Detects execution of the bash shell

any

windows-winlogbeat-*

Windows Security - Detects potential suspicious winget package installation from a suspicious

any

windows-winlogbeat-*

Windows Security - Detects the execution of Rundll32.exe

any

windows-winlogbeat-*

Windows Security - HackTool - Hashcat Password Cracker Execution

any

windows-winlogbeat-*

Windows Security - Malicious - New DLL Registered Via Odbcconf.EXE

any

windows-winlogbeat-*

Windows Security - Malicious - Odbcconf.EXE Suspicious DLL Location

any

windows-winlogbeat-*

Windows Security - Malicious - Response File Execution Via Odbcconf.EXE

any

windows-winlogbeat-*

Windows Security - Malicious - Uncommon Child Process Spawned By Odbcconf.EXE

any

windows-winlogbeat-*

Windows Security - Microsoft Malware Protection Engine Crash

any

windows-winlogbeat-*

Windows Security - Msi installation from web

any

windows-winlogbeat-*

Windows Security - Mstsc_exe execution from uncommon parent

any

windows-winlogbeat-*

Windows Security - New ODBC Driver Registered

any

windows-winlogbeat-*

Windows Security - No logs

flatline

windows-winlogbeat-*

Windows Security - Potential Access Token Abuse

any

windows-winlogbeat-*

Windows Security - Potential netcat reverse shell execution

any

windows-winlogbeat-*

Windows Security - Potential Perl Reverse Shell Execution

any

windows-winlogbeat-*

Windows Security - Potential PHP Reverse Shell

any

windows-winlogbeat-*

Windows Security - Potential Python Reverse Shell

any

windows-winlogbeat-*

Windows Security - Potential Ruby Reverse Shell

any

windows-winlogbeat-*

Windows Security - Potential SolidPDFCreator.DLL Sideloading

any

windows-winlogbeat-*

Windows Security - Potential Xterm Reverse Shell

any

windows-winlogbeat-*

Windows Security - Potentially Suspicious Network Connection To Notion API

any

windows-winlogbeat-*

Windows Security - Rorschach Ransomware Execution Activity

any

windows-winlogbeat-*

Windows Security - Suspicious Chromium Browser Instance Executed With Custom Extensions

any

windows-winlogbeat-*

Windows Security - Suspicious Driver/DLL Installation Via Odbcconf.EXE

any

windows-winlogbeat-*

Windows Security - Windows Defender Real-Time Protection Failure/Restart

any

windows-winlogbeat-*

Oracle

18 rules, from oracle.

Alert rule

Type

Index pattern

Oracle - Allocate memory ORA-00090

any

oracle-*

Oracle - Client internal error ORA-12643

any

oracle-*

Oracle - Credential failed ORA-12638

any

oracle-*

Oracle - Deadlocks ORA-00060

any

oracle-*

Oracle - Failed to allocate string oom ORA-00025

any

oracle-*

Oracle - Incorrect role password ORA-12670

any

oracle-*

Oracle - Login failure ORA-12672

any

oracle-*

Oracle - Logon denied ORA-12317

any

oracle-*

Oracle - Max db_files ORA-00059

any

oracle-*

Oracle - Max DML locks ORA-00055

any

oracle-*

Oracle - Max licenses exceeded ORA-00019

any

oracle-*

Oracle - Max log files ORA-00063

any

oracle-*

Oracle - Max processes exceeded ORA-00020

any

oracle-*

Oracle - Max sessions exceeded ORA-00018

any

oracle-*

Oracle - Max temp locks ORA-00057

any

oracle-*

Oracle - No Logs

flatline

oracle-*

Oracle - Object too large ORA-00064

any

oracle-*

Oracle - Single process login ORA-00024

any

oracle-*

Fortigate

17 rules, from fortigate.

Alert rule

Type

Index pattern

Fortigate - Attack detected

any

fortigate-*

Fortigate - Attack dropped

any

fortigate-*

Fortigate - Device configuration changed

any

fortigate-*

Fortigate - Failed login

frequency

fortigate-*

Fortigate - Firewall configuration changed

any

fortigate-*

Fortigate - Forward deny by source IP

frequency

fortigate-*

Fortigate - HTTP server attack by destination IP

frequency

fortigate-*

Fortigate - Multiple SSL VPN login failed by source IP

frequency

fortigate-*

Fortigate - Multiple tunneling by source IP

frequency

fortigate-*

Fortigate - Multiple URL blocked by source IP

frequency

fortigate-*

Fortigate - No Logs

flatline

fortigate-*

Fortigate - SSL VPN login fail

any

fortigate-*

Fortigate - Suspicious Traffic

any

fortigate-*

Fortigate - Suspicious traffic by source_IP

frequency

fortigate-*

Fortigate - Unknown tunneling settings

any

fortigate-*

Fortigate - URL blocked

any

fortigate-*

Fortigate - Virus Detected and Blocked

any

fortigate-*

Netflow

15 rules, from netflow.

Alert rule

Type

Index pattern

Netflow - DNS traffic abnormal

spike

stream-*

Netflow - First Time Seen Remote Named Pipe - Zeek

frequency

stream-*

Netflow - ICMP larger then 64b

any

stream-*

Netflow - Multiple connections from source badip

frequency

stream-*

Netflow - Multiple connections to destination badip

frequency

stream-*

Netflow - No Logs

flatline

stream-*

Netflow - Port scan

cardinality

stream-*

Netflow - Possible Impacket SecretDump Remote Activity - Zeek

frequency

stream-*

Netflow - Remote Task Creation via ATSVC Named Pipe - Zeek

frequency

stream-*

Netflow - SMB traffic

any

stream-*

Netflow - Suspicious Access to Sensitive File Extensions - Zeek

frequency

stream-*

Netflow - Too many req to port 161

frequency

stream-*

Netflow - Too many req to port 25

frequency

stream-*

Netflow - Too many req to port 53

frequency

stream-*

Netflow - Transferring Files with Credential Data via Network Shares - Zeek

frequency

stream-*

Ransomware

11 rules, from beats.

Alert rule

Type

Index pattern

Ransomware - Base64 encoded shellcode

any

windows-winlogbeat-*

Ransomware - File changes

frequency

windows-winlogbeat-*

Ransomware - Modification file short time

frequency

windows-winlogbeat-*

Ransomware - Modification registry

any

windows-winlogbeat-*

Ransomware - Netsh rdp port forwarding

any

windows-winlogbeat-*

Ransomware - New process detection

any

windows-winlogbeat-*

Ransomware - NotPetya activity

frequency

winlogbeat*

Ransomware - Operation file

any

windows-winlogbeat-*

Ransomware - Suspicious command execution

any

windows-winlogbeat-*

Ransomware - Suspicious script execution

any

windows-winlogbeat-*

Ransomware - Suspicious use of calc.exe event_id

any

windows-winlogbeat-*

Barracuda

9 rules, from barracuda.

Alert rule

Type

Index pattern

Barracuda Firewall - DNS Tunneling Detection

any

barracuda-*

Barracuda Firewall - Failed Connection Attempts

frequency

barracuda-*

Barracuda Firewall - High Volume Data Transfer

metric_aggregation

barracuda-*

Barracuda Firewall - Idle Session Timeout Pattern

cardinality

barracuda-*

Barracuda Firewall - Malicious IP Communication

any

barracuda-*

Barracuda Firewall - New Device Detection

new_term

barracuda-*

Barracuda Firewall - Protocol Anomaly

any

barracuda-*

Barracuda Firewall - Suspicious Country Communication

any

barracuda-*

Barracuda Firewall - Unusual DNS Query Volume

frequency

barracuda-*

Paloalto

8 rules, from paloalto.

Alert rule

Type

Index pattern

Paloalto - Configuration changes failed

frequency

syslog-net-fw-palo-*

Paloalto - Flood detected

frequency

syslog-net-fw-palo-*

Paloalto - No Logs

flatline

syslog-net-fw-palo-*

Paloalto - Scan detected

frequency

syslog-net-fw-palo-*

Paloalto - Spyware detected

frequency

syslog-net-fw-palo-*

Paloalto - Unauthorized configuration changed

frequency

syslog-net-fw-palo-*

Paloalto - Virus detected

frequency

syslog-net-fw-palo-*

Paloalto - Vulnerability exploit detected

frequency

syslog-net-fw-palo-*

Waystream

6 rules, from waystream.

Alert rule

Type

Index pattern

Waystream - High CPU Load

any

waystream-*

Waystream - High Fan Speed

any

waystream-*

Waystream - High Host Temperature

any

waystream-*

Waystream - High Host Voltage - High Threshold

any

waystream-*

Waystream - High Host Voltage - Low Threshold

any

waystream-*

Waystream - No Logs

flatline

waystream-*

Adaptive rules (Empowered AI)

Note

These rules use a machine-learning model trained on your own deployment’s data. The rule definition is fixed, but the anomaly threshold is specific to your environment, so detection behaviour is not identical across installations. Train and review the model before enabling.

6 adaptive rules.

Alert rule

Package

Index pattern

AI Windows-winlogbeat Text Anomaly message - All Anomalies

beats

windows-winlogbeat*

AI Windows-winlogbeat Text Anomaly message - Log anomaly score

beats

windows-winlogbeat*

AI Windows-winlogbeat Text Anomaly message - No. of rare words

beats

windows-winlogbeat*

AI Windows-winlogbeat Text Anomaly message - Word anomaly score

beats

windows-winlogbeat*

Barracuda Firewall - Received Bytes Anomaly (Empowered AI)

barracuda

barracuda-*

Barracuda Firewall - Sent Bytes Anomaly (Empowered AI)

barracuda

barracuda-*

Coverage

This catalogue lists the static rules and Empowered AI rules that ship with the following integration packages in the Energy Logserver integrations repository: Beats (Microsoft Windows, Microsoft Windows Security, Ransomware, Empowered AI), Oracle, FortiGate, NetFlow, Barracuda, Paloalto, and Waystream. Every entry is taken from the package source, so it matches what the installer imports.

It does not cover:

  • Other vendor integrations available in the product but maintained outside the shared integrations repository, for example Check Point, Cisco, FireEye, Suricata, Tenable, Watchguard, and Wazuh. Each ships its own rules. To see the exact set for one of them, open its Advanced wizard, Step 3 Alerts, on your instance.

  • Rules declared in a package manifest but not distributed with its source (AWS and Cisco ASA). Install the package through the Advanced wizard to see the rules it imports.

For a deployment’s authoritative rule set, the Alert Rules List on that instance is always the source of truth. For a higher-level overview of the alert groups the product bundles, see Working with Pre-built Alert Groups in the Alerting System chapter.