diff --git a/wazuh_evidence_collector/checker.py b/wazuh_evidence_collector/checker.py index f6034cf027b9186e67c9833e77cd5ae47be3d7bf..3877e4d0e9c016d413e0b3099b806801bb2e522c 100644 --- a/wazuh_evidence_collector/checker.py +++ b/wazuh_evidence_collector/checker.py @@ -90,7 +90,7 @@ class Checker: def check_clamd_logs_elastic(self, agent): s = Search(using=self.es, index="wazuh-alerts-*") \ .query("match", predecoder__program_name="clamd") \ - .query("match", rule__descrhosttion="Clamd restarted") \ + .query("match", rule__description="Clamd restarted") \ .query("match", agent__id=agent[0]) body = s.execute().to_dict()