definition: Requirements: "Advance" log level is required to receive these audit events.
Detection: selection: auditType.category:
'Security' auditType.action:
'Unauthorized access to a resource' condition:selection Falsepositives:
-Access attempts to non-existent repositories or due to outdated plugins. Usually "Anonymous" user is reported in the "author.name" field in most cases. Level:critical