Playbook dont works #12157
-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU26 RAM128 Storage for /200 Gb Storage for /nsm1 tb Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi team When you enable rules in the Playbook (for example, creating a new account in Windows), the event does not appear in Alerts. Although the rule is written correctly,
Query in ELK-DEVTOOLS-Console: Click the Variables button, above, to create your own variables.GET /.ds-logs-*/_eql/search Returns the necessary information, but the trigger itself does not appear in Alerts and so on for all plays I understand that this is related to the transition from Lucene to EQL, please could you direct me where to look for the problem or read redundant information on how it works now Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 7 comments 16 replies
-
Hi,
Try on the side of the windows to generate a log and check it on the kibana side and then see if is triggered on elasticalert. I hope it help. |
Beta Was this translation helpful? Give feedback.
-
I also noticed strange events on the dashboard 10 - * Missing |
Beta Was this translation helpful? Give feedback.
-
Yes, in the play I changed the value to status: test. Thank you for your prompt response |
Beta Was this translation helpful? Give feedback.
-
I did as you said: changed it to inactive status, then did so-playbook-sync, then switched it to Active, created a user on the test host. the notification did not appear in alerts -= Started: 2024-01-11 11:26:05.115871-= Active offset: 100 -= Parsed Playbook Plays: 1 -= ab382b285 Inactive - afadef0fb Inactive - 78fc4b742 Inactive - ed034dc95 -= Maintenance Summary =- Active Plays: 1Missing ElastAlert Configs: 0
|
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
sudo cat /opt/so/rules/elastalert/playbook/afadef0fb.yaml
elasticsearch_host: "10.189.96.18:9200" index: '.ds-logs-*'
|
Beta Was this translation helpful? Give feedback.
-
It seems that my own playbook for windows doesn't work now .. I had a custom one that worked, but i tested know and it doesn't work .. No alert in SOC. So from now on i can not help you cuz im on the same situation xD |
Beta Was this translation helpful? Give feedback.
It seems that my own playbook for windows doesn't work now ..
I had a custom one that worked, but i tested know and it doesn't work .. No alert in SOC.
So from now on i can not help you cuz im on the same situation xD