Today, we are going to introduce the ability to generate counts within the outcome section of a YARA-L rule in SecOps SIEM.
It is important to understand that when working with multiple events in a rule that all outcome variables that contain UDM fields must have an aggregation associated with them. Outcome variables that just contain constants do not need an aggregate function.
Follow along in the video below to see in action how to use a aggregation functions like count within a multi event rule.
Remember that count and count_distinct are just two of the aggregate functions that can be used in the outcome section. All event values must be aggregated in rules that contain multiple values. Finally, constants do not require an aggregate function, even in multi-event rules.
Check out these additional resources with more information and learning opportunities: