text code block:data_stream.dataset:network_traffic.nfs and network_traffic.nfs.rpc.cred.uid:0 and network_traffic.nfs.rpc.auth_flavor:unix and source.ip:* and destination.ip:*
Install detection rules in Elastic Security
Detect First Time Seen NFS AUTH_SYS Root UID Access in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).