Zeek MHR #10767
Zeek MHR
#10767
-
Good day all, Is there a preferred way to disable Sensoroni analyzers? Is removing the source from Thanks! |
Beta Was this translation helpful? Give feedback.
Answered by
InfosecGoon
Jul 19, 2023
Replies: 1 comment 3 replies
-
Sorry, by "Sensoroni analyzers" you mean the ones available for enrichment in the Cases interface? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Looks like that's coming from the detect-MHR.zeek framework, which is enabled by default. Try copying init.sls from /opt/so/saltstack/default/pillar/zeek/ to /opt/so/saltstack/local/pillar/zeek and removing the line that says "frameworks/files/detect-MHR".