A field condition uses an expression to match an event. For example, you might want to match to an event type like a login failure, or a source or destination IP address. For a list of the expressions you can use, see Match expressions.
The following table describes the parameters you can use in a field match condition.
Name | Type | Required | Default | Description |
|---|---|---|---|---|
| String | Yes | Not applicable | This is a field match expression that returns a true or false value. |
| String | Yes | Not applicable | You must use the parameter |
| String | No | Inherited from the parent | A comma-separated list of match expressions. It returns a string key to group items by. If it is specified, it overrides the |
In the following example, the rule looks for events where the value of xpod_ds_name is helix. If the rule sees 100 matches within a one hour period of time, it triggers an alert.
id: 123
version: 123456789
name: Trigger on 100 events
require: 1
threshold: 100
within: 1h
items:
- type: fields
match: xpod_ds_name == "helix"