Skip to content
Discussion options

You must be logged in to vote

The ability to select the data view/index is something that is being working on for sigma rules. You could write a custom Elastalert rule to target those - https://docs.securityonion.net/en/3/main/elastalert/#custom-rules and https://docs.securityonion.net/en/3/main/elastalert/#custom-rules You would want to use the alert modules.so.securityonion-es.SecurityOnionESAlerter you can see an example in /opt/so/rules/elastalert/rules

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@nayadmohamed
Comment options

Answer selected by nayadmohamed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants