Sigma rule activation in bulk #15802
-
Version2.4.211 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM16 Storage for /65 Storage for /nsm130 Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, in soc > config > server > modules > elastalertengine > enabledSigmaRules > default I can specify which rules should be enabled upon initial import, according to the documentation. Is there also a way, to add new rules in bulk later on? Changing the settings here and doing a full resync did not seem to do the trick (unless I have missed something else somewhere). Thanks! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
In the Detections module, you can filter for the rules you want to enable then click the "check all box". When you do that a bulk action drop-down will appear that let's you enable them all. |
Beta Was this translation helpful? Give feedback.
In the Detections module, you can filter for the rules you want to enable then click the "check all box". When you do that a bulk action drop-down will appear that let's you enable them all.