From 631f8841ad2f11521a0b44f009261d19daf5eefd Mon Sep 17 00:00:00 2001 From: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Date: Tue, 12 Dec 2023 12:27:18 -0500 Subject: [PATCH] updating min-stack for Okta rule (#3318) --- .../okta/initial_access_okta_fastpass_phishing.toml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/rules/integrations/okta/initial_access_okta_fastpass_phishing.toml b/rules/integrations/okta/initial_access_okta_fastpass_phishing.toml index dc6875ef138..e67cf18bd13 100644 --- a/rules/integrations/okta/initial_access_okta_fastpass_phishing.toml +++ b/rules/integrations/okta/initial_access_okta_fastpass_phishing.toml @@ -2,8 +2,8 @@ creation_date = "2023/05/07" integration = ["okta"] maturity = "production" -min_stack_comments = "New fields added: required_fields, related_integrations, setup" -min_stack_version = "8.3.0" +min_stack_comments = "Breaking change in Okta integration bumping version to ^2.0.0" +min_stack_version = "8.10.0" updated_date = "2023/11/07" [rule] @@ -38,7 +38,7 @@ timestamp_override = "event.ingested" type = "query" query = ''' -event.dataset:okta.system and event.category:authentication and +event.dataset:okta.system and event.category:authentication and okta.event_type:user.authentication.auth_via_mfa and event.outcome:failure and okta.outcome.reason:"FastPass declined phishing attempt" '''