- C-a == Ctrl-a
- M-a == Alt-a
:q close
:w write/saves
:wa[!] write/save all windows [force]
:wq write/save and close
@rule('production_sudo', | |
logs=['osquery'], | |
matchers=['pci'], | |
outputs=['s3', 'pagerduty', 'slack']) | |
def production_sudo(record): | |
table_name = record['name'] | |
tag = record['columns']['tag'] | |
return ( | |
table_name == 'linux_syslog_auth' and | |
fnmatch(tag, 'sudo*') |