refactoring alerts to reduce noise
This commit is contained in:
parent
575261ac12
commit
f71898ca70
|
@ -47,10 +47,14 @@ WHERE
|
|||
OR file.path LIKE '/dev/shm/jack_db%'
|
||||
)
|
||||
)
|
||||
AND NOT (
|
||||
file.size <= 32
|
||||
AND file.path LIKE '/dev/shm/%'
|
||||
)
|
||||
AND file.path NOT LIKE '/dev/shm/lttng-ust-wait-%'
|
||||
AND file.path NOT LIKE '/dev/shm/flatpak-%'
|
||||
AND file.path NOT LIKE '/dev/shm/libpod_rootless_lock_%'
|
||||
AND file.path NOT LIKE '/dev/shm/sem.mp-%'
|
||||
AND file.path NOT LIKE '%/../%'
|
||||
AND file.path NOT LIKE '%/./%'
|
||||
AND file.path NOT IN ('/dev/.mdadm/', '/dev/shm/libpod_lock')
|
||||
AND file.path NOT IN ('/dev/.mdadm/', '/dev/shm/libpod_lock', '/dev/shm/sem.camlock')
|
||||
|
|
|
@ -3,7 +3,7 @@
|
|||
-- false-positives:
|
||||
-- * many
|
||||
--
|
||||
-- tags: transient process state
|
||||
-- tags: transient process state extra
|
||||
-- platform: linux
|
||||
SELECT
|
||||
f.ctime AS p0_ctime,
|
||||
|
|
|
@ -3,7 +3,7 @@
|
|||
-- false-positives:
|
||||
-- * many
|
||||
--
|
||||
-- tags: transient process state
|
||||
-- tags: transient process state extra
|
||||
-- platform: darwin
|
||||
SELECT
|
||||
f.ctime,
|
||||
|
|
Loading…
Reference in New Issue