Hello peeps
for the last week I have been struggling with creating a custom ruls for Hyper v events on Wazuh
Samples:
<group name="win\_evt\_channel,windows,local,syslog,sshd,system\_error,">
<rule id="100100" level="10">
<field name="win.system.eventID">^15268$|^19070$|^19090$</field>
<options>no_full_log</options>
<description>From Test4.</description>
</rule>
<rule id="100200" level="13">
<field name="win.system.severityValue">^INFORMATION$</field>
<options>no_full_log</options>
<description>From test4.</description>
</rule>
<rule id="100300" level="10">
<field name="win.eventdata.workstationName" type="pcre2">.+</field>
<description>Test4</description>
</rule>
<rule id="100400" level="10">
<field name="win.system.eventID" type="pcre2">^15268$|^19070$|^19090$</field>
<description>Test4</description>
</rule>
<rule id="100500" level="10">
<match>^15268$|^19070$|^19090$</match>
<description>Test4</description>
</rule>
<rule id="100600" level="10">
<match>^19090</match>
<description>Test4</description>
</rule>
<rule id="100700" level="10">
<match>19090</match>
<description>Test4</description>
</rule>
<rule id="100800" level="10">
<field name="win.system.severityValue">^INFORMATION$</field>
<description>Test4</description>
</rule>
<rule id="100900" level="10">
<field name="win.system.severityValue">^ERROR$</field>
<description>Test4</description>
</rule>
<rule id="101000" level="10">
<field name="win.system.providerName">^Hyper-V-VMMS$</field>
<field name="win.system.eventID">^19070$|^19090$</field>
<description>Test4</description>
</rule>
</group>
Idk why any of the rules above is giving any alert even though I choose a very frequent event like 19090.
hope any1 can help pls
thanks in advance.
<group name="win\_evt\_channel,windows,local,syslog,sshd,system\_error,">

