Jake Mowrer f0bc757c83
Update custom-detection-rules.md
Adding verbiage about the requirement that the query must return specific fields for each row for it to work.  Line 29
2019-08-19 14:22:46 -05:00
..
2019-06-04 22:13:57 +00:00
2019-06-04 22:13:57 +00:00
2019-08-16 02:33:19 -04:00
2019-06-25 13:44:19 -07:00
2019-06-17 12:42:08 -04:00
2019-08-09 12:00:09 -07:00
2019-06-04 22:13:57 +00:00
2019-06-25 13:44:19 -07:00
2019-06-04 22:13:57 +00:00
2019-06-04 22:13:57 +00:00
2019-08-12 19:12:38 -04:00
2019-08-19 14:22:46 -05:00
2019-06-04 22:13:57 +00:00
2019-08-09 12:00:09 -07:00