2.4 Elastalert Yaml #12867
-
Version2.4.60 Installation MethodNetwork installation on Ubuntu Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM20 Storage for /1tb Storage for /nsm800gb Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, Fresh install of Security Onion 2.4.6 - the last time I properly use in anger was about 10 years ago so things have changed. I am really struggling to get the elastalerts to work sending emails. I have confirmed the connectivity and email account details etc. But when I install a yaml (even tried a version of the cardinality_alerts.yaml that i found linked to one of these forum posts) it kills the so-elastalert status - changes it to missing. a review of elastalert.log only moaned about the smtp_auth_file.txt file path - which I resolved. Now it appears whenever I add any .yaml to the rules it kills the service. Does anyone have a working 2.4 email alerting yaml they could share so I can check where I'm potentially going wrong please? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
There is an example of setting up external email alerting for elastalert rules in the docs at https://docs.securityonion.net/en/2.4/elastalert.html#email-external Here is an example rule that would send an email anytime the rule.uuid 2100498 is seen. If you are creating your alert using playbook then you need to add the email portion by editing the yaml file in
|
Beta Was this translation helpful? Give feedback.
-
is the email portion added in the rule.yaml file (33520538d.yaml in this case) or in the generic.template file? i try adding the email portion in the rule.yaml file but the test will fail |
Beta Was this translation helpful? Give feedback.
There is an example of setting up external email alerting for elastalert rules in the docs at https://docs.securityonion.net/en/2.4/elastalert.html#email-external
Here is an example rule that would send an email anytime the rule.uuid 2100498 is seen. If you are creating your alert using playbook then you need to add the email portion by editing the yaml file in
/opt/so/rules/elastalert/playbook/