Skip to content
S03D4-164 edited this page Apr 30, 2020 · 1 revision

Events detected as defined by the detection rules are displayed.

Detection rules can be created by "Save as Detection Rule" in Search.

Events are detected by collection_alert_data.py configured in crontab upon installation.

When collection_alert_data.py is executed, events that match the detection rules will be saved in the alert index.

Clone this wiki locally