Can you trigger a script based on specific event IDs? #10276
Replies: 1 comment 2 replies
-
You could probably put something together with Elastalert to do this -- create the Play in Playbook and then update the rule to use the HTTP alerter or something to fire off a script. Do you have access to a SOAR platform or anything else with an addressable API that could do this? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
This may be a silly question, but has anyone tried to trigger a script based on specific events/alerts? The idea would be to script disabling switchports when specific event IDs from a firewall or cloud AV are seen by Security Onion. I'm not sure if this is practical or even doable with Security Onion, but I figured I'd ask before jumping down a rabbit hole. Thanks.
Beta Was this translation helpful? Give feedback.
All reactions