cscli scenarios install bouddha-fr/opensearch-dashboard-bfDetect failed OpenSearch dashboard authentications:
1# OpenSearch web auth bruteforce2type: leaky3name: bouddha-fr/opensearch-dashboard-bf4description: "Detect bruteforce attempts on OpenSearch web interface"5filter: evt.Meta.log_type == 'opensearch_failed_auth'6leakspeed: "10s"7capacity: 58groupby: evt.Meta.source_ip9blackhole: 5m10labels:11 remediation: true12 confidence: 313 spoofable: 014 classification:15 - attack.T111016 behavior: "http:bruteforce"17 label: "OpenSearch Bruteforce"18 service: opensearch19