Predefined Alert Rules
Overview
Every Energy Logserver integration package ships a set of predefined alert rules that detect common threats and operational problems for the data source it handles. When you install an integration, its installer imports these rules into the Alert Rules List, so you do not have to write detection logic from scratch.
This chapter catalogues those rules. For how alerting works and how to build your own, see Alerting System.
Where the rules come from
Access: ELS Console → SIEM → Integrations → (select an integration) → Advanced → Step 3 Alerts
The Advanced wizard lists the rules bundled with an integration before you install them. After installation they appear in SIEM → Alerts → Alert Rules List, grouped by the value in each rule’s Group Name. This catalogue uses the same grouping.
Two classes of rule
The rules split into two kinds, and the difference matters when you plan detection:
Static rules install exactly as written: a fixed query against a fixed index pattern. Behaviour is identical on every deployment. These are catalogued below by group.
Adaptive rules (Empowered AI) use a machine-learning model trained on your own data. The rule definition is fixed, but the anomaly threshold is specific to your environment, so behaviour is not identical across installations. These are listed in their own section.
Reading the tables
Each static table lists the rules in one group:
Alert rule: the name as it appears in the Alert Rules List.
Type: the detection method (
frequency,any,flatline,spike,cardinality,new_term,metric_aggregation).Index pattern: the indices the rule queries.
All predefined rules install disabled. Review each rule, adjust its filters and notification method for your environment, then enable it. The default importance is 100 unless a rule states otherwise.
Note
This catalogue reflects the integration packages that ship their rule definitions in the Energy Logserver integrations repository. Rules are versioned with their package, so names and counts can change between releases. See Coverage for what is included and what is not.
Static alert rules by group
151 static rules across 9 groups. Each installs exactly as listed; adjust filters and notification method for your environment, then enable it.
Microsoft Windows
36 rules, from beats.
Alert rule |
Type |
Index pattern |
|---|---|---|
Windows - Account lock |
any |
|
Windows - Admin night logon |
any |
|
Windows - Admin task as user |
any |
|
Windows - Application error |
any |
|
Windows - Application hang |
any |
|
Windows - Audit policy changed |
any |
|
Windows - Code integrity changed |
any |
|
Windows - Diff IPs logon |
cardinality |
|
Windows - Driver loaded |
any |
|
Windows - Event service error |
any |
|
Windows - Eventlog service stopped |
any |
|
Windows - file insufficient privileges |
frequency |
|
Windows - Firewall rule add |
any |
|
Windows - Firewall rule deleted |
any |
|
Windows - Firewall rule modified |
any |
|
Windows - Kerberos pre-authentication failed |
any |
|
Windows - Login with explicit credentials |
any |
|
Windows - Logs deleted |
any |
|
Windows - Member added to a security-enabled global group |
any |
|
Windows - Member added to a security-enabled local group |
any |
|
Windows - Member added to a security-enabled universal group |
any |
|
Windows - New device |
any |
|
Windows - New service installed |
any |
|
Windows - No Logs |
flatline |
|
Windows - Package installation |
any |
|
Windows - Password policy change |
any |
|
Windows - Reset password attempt |
any |
|
Windows - Security local group was changed |
any |
|
Windows - Security log full |
any |
|
Windows - Start up |
any |
|
Windows - SUNBURST Fingerprint |
any |
|
Windows - System has been shutdown |
any |
|
Windows - The system time was changed |
any |
|
Windows TaskScheduler - Task created |
any |
|
Windows TaskScheduler - Task deleted |
any |
|
Windows TaskScheduler - Task executed |
any |
|
Microsoft Windows Security
31 rules, from beats.
Alert rule |
Type |
Index pattern |
|---|---|---|
Windows Security - Connection initiated via certutil_exe |
any |
|
Windows Security - Detect outbound rdp connections over non standard tools |
any |
|
Windows Security - Detect RDP file creation from suspicious application |
any |
|
Windows Security - Detect rootkit Moriya |
any |
|
Windows Security - Detection of relevant antivirus events |
any |
|
Windows Security - Detects execution of the bash shell |
any |
|
Windows Security - Detects potential suspicious winget package installation from a suspicious |
any |
|
Windows Security - Detects the execution of Rundll32.exe |
any |
|
Windows Security - HackTool - Hashcat Password Cracker Execution |
any |
|
Windows Security - Malicious - New DLL Registered Via Odbcconf.EXE |
any |
|
Windows Security - Malicious - Odbcconf.EXE Suspicious DLL Location |
any |
|
Windows Security - Malicious - Response File Execution Via Odbcconf.EXE |
any |
|
Windows Security - Malicious - Uncommon Child Process Spawned By Odbcconf.EXE |
any |
|
Windows Security - Microsoft Malware Protection Engine Crash |
any |
|
Windows Security - Msi installation from web |
any |
|
Windows Security - Mstsc_exe execution from uncommon parent |
any |
|
Windows Security - New ODBC Driver Registered |
any |
|
Windows Security - No logs |
flatline |
|
Windows Security - Potential Access Token Abuse |
any |
|
Windows Security - Potential netcat reverse shell execution |
any |
|
Windows Security - Potential Perl Reverse Shell Execution |
any |
|
Windows Security - Potential PHP Reverse Shell |
any |
|
Windows Security - Potential Python Reverse Shell |
any |
|
Windows Security - Potential Ruby Reverse Shell |
any |
|
Windows Security - Potential SolidPDFCreator.DLL Sideloading |
any |
|
Windows Security - Potential Xterm Reverse Shell |
any |
|
Windows Security - Potentially Suspicious Network Connection To Notion API |
any |
|
Windows Security - Rorschach Ransomware Execution Activity |
any |
|
Windows Security - Suspicious Chromium Browser Instance Executed With Custom Extensions |
any |
|
Windows Security - Suspicious Driver/DLL Installation Via Odbcconf.EXE |
any |
|
Windows Security - Windows Defender Real-Time Protection Failure/Restart |
any |
|
Oracle
18 rules, from oracle.
Alert rule |
Type |
Index pattern |
|---|---|---|
Oracle - Allocate memory ORA-00090 |
any |
|
Oracle - Client internal error ORA-12643 |
any |
|
Oracle - Credential failed ORA-12638 |
any |
|
Oracle - Deadlocks ORA-00060 |
any |
|
Oracle - Failed to allocate string oom ORA-00025 |
any |
|
Oracle - Incorrect role password ORA-12670 |
any |
|
Oracle - Login failure ORA-12672 |
any |
|
Oracle - Logon denied ORA-12317 |
any |
|
Oracle - Max db_files ORA-00059 |
any |
|
Oracle - Max DML locks ORA-00055 |
any |
|
Oracle - Max licenses exceeded ORA-00019 |
any |
|
Oracle - Max log files ORA-00063 |
any |
|
Oracle - Max processes exceeded ORA-00020 |
any |
|
Oracle - Max sessions exceeded ORA-00018 |
any |
|
Oracle - Max temp locks ORA-00057 |
any |
|
Oracle - No Logs |
flatline |
|
Oracle - Object too large ORA-00064 |
any |
|
Oracle - Single process login ORA-00024 |
any |
|
Fortigate
17 rules, from fortigate.
Alert rule |
Type |
Index pattern |
|---|---|---|
Fortigate - Attack detected |
any |
|
Fortigate - Attack dropped |
any |
|
Fortigate - Device configuration changed |
any |
|
Fortigate - Failed login |
frequency |
|
Fortigate - Firewall configuration changed |
any |
|
Fortigate - Forward deny by source IP |
frequency |
|
Fortigate - HTTP server attack by destination IP |
frequency |
|
Fortigate - Multiple SSL VPN login failed by source IP |
frequency |
|
Fortigate - Multiple tunneling by source IP |
frequency |
|
Fortigate - Multiple URL blocked by source IP |
frequency |
|
Fortigate - No Logs |
flatline |
|
Fortigate - SSL VPN login fail |
any |
|
Fortigate - Suspicious Traffic |
any |
|
Fortigate - Suspicious traffic by source_IP |
frequency |
|
Fortigate - Unknown tunneling settings |
any |
|
Fortigate - URL blocked |
any |
|
Fortigate - Virus Detected and Blocked |
any |
|
Netflow
15 rules, from netflow.
Alert rule |
Type |
Index pattern |
|---|---|---|
Netflow - DNS traffic abnormal |
spike |
|
Netflow - First Time Seen Remote Named Pipe - Zeek |
frequency |
|
Netflow - ICMP larger then 64b |
any |
|
Netflow - Multiple connections from source badip |
frequency |
|
Netflow - Multiple connections to destination badip |
frequency |
|
Netflow - No Logs |
flatline |
|
Netflow - Port scan |
cardinality |
|
Netflow - Possible Impacket SecretDump Remote Activity - Zeek |
frequency |
|
Netflow - Remote Task Creation via ATSVC Named Pipe - Zeek |
frequency |
|
Netflow - SMB traffic |
any |
|
Netflow - Suspicious Access to Sensitive File Extensions - Zeek |
frequency |
|
Netflow - Too many req to port 161 |
frequency |
|
Netflow - Too many req to port 25 |
frequency |
|
Netflow - Too many req to port 53 |
frequency |
|
Netflow - Transferring Files with Credential Data via Network Shares - Zeek |
frequency |
|
Ransomware
11 rules, from beats.
Alert rule |
Type |
Index pattern |
|---|---|---|
Ransomware - Base64 encoded shellcode |
any |
|
Ransomware - File changes |
frequency |
|
Ransomware - Modification file short time |
frequency |
|
Ransomware - Modification registry |
any |
|
Ransomware - Netsh rdp port forwarding |
any |
|
Ransomware - New process detection |
any |
|
Ransomware - NotPetya activity |
frequency |
|
Ransomware - Operation file |
any |
|
Ransomware - Suspicious command execution |
any |
|
Ransomware - Suspicious script execution |
any |
|
Ransomware - Suspicious use of calc.exe event_id |
any |
|
Barracuda
9 rules, from barracuda.
Alert rule |
Type |
Index pattern |
|---|---|---|
Barracuda Firewall - DNS Tunneling Detection |
any |
|
Barracuda Firewall - Failed Connection Attempts |
frequency |
|
Barracuda Firewall - High Volume Data Transfer |
metric_aggregation |
|
Barracuda Firewall - Idle Session Timeout Pattern |
cardinality |
|
Barracuda Firewall - Malicious IP Communication |
any |
|
Barracuda Firewall - New Device Detection |
new_term |
|
Barracuda Firewall - Protocol Anomaly |
any |
|
Barracuda Firewall - Suspicious Country Communication |
any |
|
Barracuda Firewall - Unusual DNS Query Volume |
frequency |
|
Paloalto
8 rules, from paloalto.
Alert rule |
Type |
Index pattern |
|---|---|---|
Paloalto - Configuration changes failed |
frequency |
|
Paloalto - Flood detected |
frequency |
|
Paloalto - No Logs |
flatline |
|
Paloalto - Scan detected |
frequency |
|
Paloalto - Spyware detected |
frequency |
|
Paloalto - Unauthorized configuration changed |
frequency |
|
Paloalto - Virus detected |
frequency |
|
Paloalto - Vulnerability exploit detected |
frequency |
|
Waystream
6 rules, from waystream.
Alert rule |
Type |
Index pattern |
|---|---|---|
Waystream - High CPU Load |
any |
|
Waystream - High Fan Speed |
any |
|
Waystream - High Host Temperature |
any |
|
Waystream - High Host Voltage - High Threshold |
any |
|
Waystream - High Host Voltage - Low Threshold |
any |
|
Waystream - No Logs |
flatline |
|
Adaptive rules (Empowered AI)
Note
These rules use a machine-learning model trained on your own deployment’s data. The rule definition is fixed, but the anomaly threshold is specific to your environment, so detection behaviour is not identical across installations. Train and review the model before enabling.
6 adaptive rules.
Alert rule |
Package |
Index pattern |
|---|---|---|
AI Windows-winlogbeat Text Anomaly message - All Anomalies |
|
|
AI Windows-winlogbeat Text Anomaly message - Log anomaly score |
|
|
AI Windows-winlogbeat Text Anomaly message - No. of rare words |
|
|
AI Windows-winlogbeat Text Anomaly message - Word anomaly score |
|
|
Barracuda Firewall - Received Bytes Anomaly (Empowered AI) |
|
|
Barracuda Firewall - Sent Bytes Anomaly (Empowered AI) |
|
|
Coverage
This catalogue lists the static rules and Empowered AI rules that ship with the following integration packages in the Energy Logserver integrations repository: Beats (Microsoft Windows, Microsoft Windows Security, Ransomware, Empowered AI), Oracle, FortiGate, NetFlow, Barracuda, Paloalto, and Waystream. Every entry is taken from the package source, so it matches what the installer imports.
It does not cover:
Other vendor integrations available in the product but maintained outside the shared integrations repository, for example Check Point, Cisco, FireEye, Suricata, Tenable, Watchguard, and Wazuh. Each ships its own rules. To see the exact set for one of them, open its Advanced wizard, Step 3 Alerts, on your instance.
Rules declared in a package manifest but not distributed with its source (AWS and Cisco ASA). Install the package through the Advanced wizard to see the rules it imports.
For a deployment’s authoritative rule set, the Alert Rules List on that instance is always the source of truth. For a higher-level overview of the alert groups the product bundles, see Working with Pre-built Alert Groups in the Alerting System chapter.