-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM128Gb Storage for /96Gb Storage for /nsm814Gb Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi! I need some help with our Secure Onion 2.4.30 host. I set up almost all we need. Last critical option we need is email notifications for alerts. I read documentation, where I saw how to set notification type for every rule. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 5 replies
-
Hi,you can add the email alerting to the generic.template on path /opt/so/rules/elastalert/playbook/. |
Beta Was this translation helpful? Give feedback.
Hi,you can add the email alerting to the generic.template on path /opt/so/rules/elastalert/playbook/.
But I guess you have to deactivate and activate the rules again to get them parsed again.
Another option would be to create a single elastalert config which triggers when an alert gets written to the es-index.