A cardinality condition counts unique field values. When the count is met, the rule triggers an alert. The following table describes the parameters you can use in a cardinality condition.
Name | Type | Required | Default | Description |
|---|---|---|---|---|
| List | Yes | Not applicable | A field, correlation, deviation, or cardinality. |
| String | No | Inherited from the parent | A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the |
| Number | Yes | Not applicable | Cardinality count at which trigger occurs. The value must be a positive integer. |
| String | Yes | Not applicable | A match expression used to group the cardinality. |
| Boolean | No | True | Whether to treat the value of |
In the following example, the rule looks for five successful log in attempts from the same IP address within a five minute period of time, and groups the results by IP address. The results are then grouped by username.
id: 1234567
version: 6789010
name: O365 - Suspicious User login from Multiple IP Addresses
groupby: username
require: 1
within: 600s
items:
- type: cardinality
item:
- type: fields
match: class == "ms_office365" && action contains "userloggedin" && result == "success"
require: 5
cardinalityGroupby: srcipv4