wazuh / wazuh-documentation

Wazuh - Project documentation
https://wazuh.com
195 stars 347 forks source link

Update ruleset documentation to alarify time and weekday Options #7892

Open JcabreraC opened 3 days ago

JcabreraC commented 3 days ago

Description:

The current Wazuh ruleset documentation needs an update to clarify how the time and weekday options evaluate events based on the timestamp. It should be explicitly stated that these options use the timestamp from the moment the event is processed by the manager, not the timestamp embedded within the event itself. This clarification will help users understand the operational context of these options and prevent potential confusion about their functionality.

Objectives:

Tasks:

  1. Documentation Update: Amend the sections that describe the time and weekday options in the Wazuh ruleset documentation.
  2. Technical Review: Ensure that the updated descriptions accurately reflect the implementation and usage of these options.
  3. Consistency Check: Review other parts of the documentation to ensure consistency in how time-related options are described across the board.

Expected Outcome:

DoD (Definition of Done):

This update will ensure users have the correct understanding of how timing conditions are applied within Wazuh rules, leading to more effective and accurate configurations.

Dwordcito commented 2 days ago

Target 4.9 documentation, hot change.