1
- ___
1
+ ---
2
2
layout : " sumologic"
3
3
page_title : " SumoLogic: sumologic_cse_outlier_rule"
4
4
description : |-
@@ -10,31 +10,32 @@ Provides a Sumo Logic CSE [Outlier Rule](https://help.sumologic.com/docs/cse/rul
10
10
11
11
## Example Usage
12
12
``` hcl
13
- resource "sumologic_cse_first_seen_rule" "first_seen_rule" {
13
+ resource "sumologic_cse_outlier_rule" "outlier_rule" {
14
+ name = "Outlier Rule Example"
15
+ name_expression = "Signal name"
16
+ description_expression = "Signal description"
17
+ enabled = true
18
+ baseline_window_size = "2592000000"
19
+ floor_value = 3
20
+ deviation_threshold = 3
21
+ is_prototype = false
22
+ match_expression = "objectType = \"Network\""
23
+ retention_window_size = "7776000000"
24
+ window_size = "T60M"
25
+ severity = 3
26
+ summary_expression = "Signal summary"
14
27
aggregation_functions {
15
- name = "total"
16
- function = "count"
17
- arguments = ["true"]
28
+ arguments = [
29
+ "true",
30
+ ]
31
+ function = "count"
32
+ name = "current"
18
33
}
19
- baseline_window_size = "1209600000" // 14 days
20
- description_expression = "Spike in Login Failures - {{ user_username }}"
21
- enabled = true
22
34
entity_selectors {
23
35
entity_type = "_username"
24
- expression = "user_username"
36
+ expression = "user_username"
25
37
}
26
- floor_value = 0
27
- deviation_threshold = 3
28
- group_by_fields = ["user_username"]
29
- is_prototype = false
30
- match_expression = "objectType=\"Authentication\" AND success=false"
31
- name = "Spike in Login Failures"
32
- name_expression = "Spike in Login Failures - {{ user_username }}"
33
- retention_window_size = "7776000000" // 90 days
34
- severity = 1
35
- summary_expression = "Spike in Login Failures - {{ user_username }}"
36
- window_size = "T24H"
37
- suppression_window_size = 90000000
38
+ tags = ["_mitreAttackTactic:TA0005"]
38
39
}
39
40
```
40
41
## Argument Reference
0 commit comments