Deviation conditions look for changes to numeric values. For example, if you specify aggregate to be cardinality, this counts the number of unique values in a string, IP address, or other types of fields. This count is the numeric value that a deviation condition tests against. A deviation condition establishes an average baseline for the selected value and then looks for deviations from that baseline. To create the baseline, the condition creates a series of buckets that each cover a fixed period of time. The value from each event is then added to the appropriate bucket based on the timestamp of the event, and the average value and standard deviation for each bucket is calculated. When any one bucket deviates from the average of all buckets by the defined threshold, the condition triggers. You can select the number of buckets and the time period that each bucket covers. For example, 60 buckets each covering a 1 minute time period could detect the average of any one minute period deviating from the average for one hour either side of it.
The following table describes the parameters you can use in a deviation condition.
Name | Type | Required | Default | Description |
|---|---|---|---|---|
| List | Yes | Not applicable | A field, correlation, deviation, or cardinality. |
| String | No | Inherited from the parent | A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the |
| String | Yes | Not applicable | The name of the filed being counted. |
| String | Yes | Not applicable | The type of aggregation to perform on the field: cardinality, sum, or average. |
| String | Yes | False | A comparison expression comparing either stddev (standard deviation), percent, or count with a value. For example, |
| Duration | No | 1 minute | The period of time the bucket covers. The value must be a positive integer, followed by s (second), m (minute), or h (hour). |
| Number | No | 1 | The number of buckets. The value must be a positive integer. |
In the following example, the rule looks for multiple host remote desktop log in attempts on the same user account. It creates five buckets each covering five minutes, and for each log in attempt looks for the parameters metaclass to equal windows, and eventid to equal 4624, and logontypeid to equal 10, and any field except username to end with $, and for there to be a field called hostname. Once the standard deviation of the hostname parameter varies by greater than five in any of the five buckets, the rule triggers. For each trigger of the rule, the results are grouped by username.
id: 12345678
version: 1676294234
name: Multiple Host RDP logins on same user account
groupby: username
require: 1
within: 600s
items:
- type: deviation
item:
- type: fields
match: >
metaclass == "windows" && eventid == "4624" && logontypeid == 10 &&
(not username endsWith `$`) && has(hostname)
field: hostname
aggregate: cardinality
condition: stddev > 5
bucketSize: 5m
bucketCount: 5