Playbook: Elastalert config is not adapted to the sigma rule and SO filter #10007
Replies: 1 comment 1 reply
-
Could you expand on "I applied a SO filter a while back" a bit? What kind of filter? On which Playbook play? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello All,
I applied a SO filter a while back, now I added some values to the filter, but I don't see these values appear in the field "ElastAlert Config". I see the Elastalert config without the added new values.
Even if I remove the complete SO filter, the elastalert config is not modified. This means that another rule contains an error that blocks or stops the script.
I also discovered in the playbook sync log that multiple rules are without a elastalert config (5). I'm sure these rules had a config because some of them have a SO filter, so they have triggered a false positive in the past.
You will not get any visual errors in playbook if the elastalert script does not convert the sigma rule correct to elastalert config.
I've already searched the following logs:
Playbook:
Elastalert:
Where can I find which rule causes this? witch log source?
Regards
Bart
Beta Was this translation helpful? Give feedback.
All reactions