crowdsec/pkg/leakybucket/tests/simple-trigger-external-data/bucket.yaml

14 lines
419 B
YAML
Raw Normal View History

type: trigger
debug: true
name: test/simple-trigger
data:
- source_url: https://invalid.com/test.list
dest_file: simple-trigger-external-data/simple_patterns.txt
2020-08-23 21:42:24 +00:00
type: string
description: "Simple trigger with external data"
filter: "evt.Line.Labels.type =='testlog' && evt.Parsed.tainted_data in File('simple-trigger-external-data/simple_patterns.txt')"
groupby: evt.Meta.source_ip
labels:
type: overflow_1