Security Onion Pro and Notifications #13105
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /250Gb Storage for /nsm1Tb Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI notice that "Notifications" are now a Security Onion Pro licensed feature. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
This feature is just for the gui portion and includes other alerters other than just smtp. You can continue using your old rules and drop them in the custom folder in /opt/so/conf/elastalert/custom. If you want to manage your elastalert rules with Detections then you will need to use sed or something like that to modify the files once they are placed in the normal location. |
Beta Was this translation helpful? Give feedback.
-
Ok thanks, we have a set of webhooks for ServiceNow that we use to generate tickets for High and Severe NIDS events. |
Beta Was this translation helpful? Give feedback.
This feature is just for the gui portion and includes other alerters other than just smtp. You can continue using your old rules and drop them in the custom folder in /opt/so/conf/elastalert/custom. If you want to manage your elastalert rules with Detections then you will need to use sed or something like that to modify the files once they are placed in the normal location.