title: test id: ff151c33-45fa-475d-af4f-c2f93571f4fe description: | condition count status: experimental date: 2021/12/4 author: test logsource: product: windows service: security detection: selection1: EventID: 3 selection2: aaa: bbb condition: selection1 and not selection2 | count(TEAMNAME) by HOGE < 3 falsepositives: - Unknown level: medium