60000) that is triggered by windows_eventchannel events. You also need an additional rule to prevent the triggering of similar rules. The following should give you the result you expect: <rule id="100007" level="0">
<if_sid>60000</if_sid>
<field name="win.system.channel">^Kaspersky Event Log$</field>
<options>no_full_log</options>
<description>Kapersky rule for the System channel</description>
</rule>
<rule id="100008" level="10">
<if_sid>100007</if_sid>
<field name="win.system.providerName">klnagent</field>
<field name="win.system.eventID">1</field>
<description>Kaspersky Agent Restarted</description>
</rule>{"win":{"system":{"providerName":"klnagent","eventID":"1","level":"4","task":"0","keywords":"0x80000000000000","systemTime":"2019-06-05T15:47:59.000000000Z","eventRecordID":"26424","channel":"Kaspersky Event Log","computer":"share.plasmec-int.it","severityValue":"INFORMATION","message":"Application 'Kaspersky Security 10 for Windows Server' started"},"eventdata":{"data":"Application 'Kaspersky Security 10 for Windows Server' started"}}}
**Phase 1: Completed pre-decoding.
full event: '{"win":{"system":{"providerName":"klnagent","eventID":"1","level":"4","task":"0","keywords":"0x80000000000000","systemTime":"2019-06-05T15:47:59.000000000Z","eventRecordID":"26424","channel":"Kaspersky Event Log","computer":"share.plasmec-int.it","severityValue":"INFORMATION","message":"Application 'Kaspersky Security 10 for Windows Server' started"},"eventdata":{"data":"Application 'Kaspersky Security 10 for Windows Server' started"}}}'
timestamp: '(null)'
hostname: 'littlePill'
program_name: '(null)'
log: '{"win":{"system":{"providerName":"klnagent","eventID":"1","level":"4","task":"0","keywords":"0x80000000000000","systemTime":"2019-06-05T15:47:59.000000000Z","eventRecordID":"26424","channel":"Kaspersky Event Log","computer":"share.plasmec-int.it","severityValue":"INFORMATION","message":"Application 'Kaspersky Security 10 for Windows Server' started"},"eventdata":{"data":"Application 'Kaspersky Security 10 for Windows Server' started"}}}'
**Phase 2: Completed decoding.
decoder: 'json'
win.system.providerName: 'klnagent'
win.system.eventID: '1'
win.system.level: '4'
win.system.task: '0'
win.system.keywords: '0x80000000000000'
win.system.systemTime: '2019-06-05T15:47:59.000000000Z'
win.system.eventRecordID: '26424'
win.system.channel: 'Kaspersky Event Log'
win.system.computer: 'share.plasmec-int.it'
win.system.severityValue: 'INFORMATION'
win.system.message: 'Application 'Kaspersky Security 10 for Windows Server' started'
win.eventdata.data: 'Application 'Kaspersky Security 10 for Windows Server' started'
**Phase 3: Completed filtering (rules).
Rule id: '100008'
Level: '10'
Description: 'Kaspersky Agent Restarted'
**Alert to be generated.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/G5s5xoG_mak/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2b5fbf99-ebdb-4556-acbc-face72e5d51a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
**Phase 1: Completed pre-decoding.
full event: '{"win":{"system":{"providerName":"klnagent","eventID":"1","level":"4","task":"0","keywords":"0x80000000000000","systemTime":"2019-06-05T15:47:59.000000000Z","eventRecordID":"26424","channel":"Kaspersky Event Log","computer":"share.plasmec-int.it","severityValue":"INFORMATION","message":"Application 'Kaspersky Security 10 for Windows Server' started"},"eventdata":{"data":"Application 'Kaspersky Security 10 for Windows Server' started"}}}'
timestamp: '(null)'
hostname: 'littlePill'
program_name: '(null)'
log: '{"win":{"system":{"providerName":"klnagent","eventID":"1","level":"4","task":"0","keywords":"0x80000000000000","systemTime":"2019-06-05T15:47:59.000000000Z","eventRecordID":"26424","channel":"Kaspersky Event Log","computer":"share.plasmec-int.it","severityValue":"INFORMATION","message":"Application 'Kaspersky Security 10 for Windows Server' started"},"eventdata":{"data":"Application 'Kaspersky Security 10 for Windows Server' started"}}}'
**Phase 2: Completed decoding.
decoder: 'json'
win.system.providerName: 'klnagent'
win.system.eventID: '1'
win.system.level: '4'
win.system.task: '0'
win.system.keywords: '0x80000000000000'
win.system.systemTime: '2019-06-05T15:47:59.000000000Z'
win.system.eventRecordID: '26424'
win.system.channel: 'Kaspersky Event Log'
win.system.computer: 'share.plasmec-int.it'
win.system.severityValue: 'INFORMATION'
win.system.message: 'Application 'Kaspersky Security 10 for Windows Server' started'
win.eventdata.data: 'Application 'Kaspersky Security 10 for Windows Server' started'
**Phase 3: Completed filtering (rules).
Rule id: '100007'
Level: '10'
Description: 'Kaspersky Agent Restarted'
**Alert to be generated.
To unsubscribe from this group and all its topics, send an email to wazuh+unsubscribe@googlegroups.com.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2b5fbf99-ebdb-4556-acbc-face72e5d51a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/G5s5xoG_mak/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/11a6bf9a-b1da-4765-923c-5dc138e679d6%40googlegroups.com.