Hello Stefanny,
The rules should look like this
<group name="windows,logon_unusual_detection,">
<rule id="100011" level="3" ignore="120">
<if_sid>31102</if_sid>
<field name="win.eventdata.logonType" type="pcre2">^4|^5|^6|^7|^8|^9|^10|^11</field>
<options>no_alert</options>
<description>Aux: Logon Type Inusual (4,5,6,7,8,9,10,11)</description>
</rule>
<rule id="100012" level="3" ignore="120">
<if_sid>31102</if_sid>
<list field="win.eventdata.targetUserName" type="pcre2" lookup="match_key_value">etc/lists/domain_admins.txt</list>
<options>no_log</options>
<description>Aux: Logon de Cuenta de Domain Admin</description>
</rule>
<rule id="100013" level="3" ignore="120">
<if_sid>31102</if_sid>
<time>00:00-07:59</time>
<options>no_log</options>
<description>Aux: Logon Fuera de Horario Laboral (Non-business hours)</description>
</rule>
<rule id="100014" level="3" ignore="120">
<if_sid>31102</if_sid>
<time>20:00-23:59</time>
<options>no_log</options>
<description>Aux: Logon Fuera de Horario Laboral (Non-business hours)</description>
</rule>
</group>
Regards