Sigma Rule Alerts (old playbook) are are grayed out for "Tune Detection" #13127
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 v-CPU RAM48 GB Storage for /250 GB Storage for /nsm1.66 TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello all, After the upgrade i wanted to tune a sigma rule that is creating a lot of noise, but the "Tune Detection" is grayed out. It is also only for sigma rules, the suricata rules can be tuned The status of all my rules is "OK" I looked for a solution in the documentation but couldn't find it Regards Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 25 replies
-
This is expected. The old Playbook rules should no longer be active and should not be generating any more alerts. |
Beta Was this translation helpful? Give feedback.
-
@sleepingbel Did you enable any Playbook Plays after soup? Im just trying to understand why it didnt back them up. |
Beta Was this translation helpful? Give feedback.
-
Yes the original install was 2.4.50Met vriendelijke groeten Bart Van Hees Met vriendelijke groeten Bart Van Hees Op 11 jun. 2024 om 12:25 heeft Josh Brower ***@***.***> het volgende geschreven:
@sleepingbel Do you recall what version you did the initial install from?
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you were mentioned.Message ID: ***@***.***>
|
Beta Was this translation helpful? Give feedback.
-
Hey Josh,I aim not sure what you mean with interactively but I did a ssh to the server and entered the command sudo soup and waited until soup finished Met vriendelijke groeten Bart Van Hees Op 11 jun. 2024 om 13:56 heeft Josh Brower ***@***.***> het volgende geschreven:
How did you run soup? Interactively?
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you were mentioned.Message ID: ***@***.***>
|
Beta Was this translation helpful? Give feedback.
all the rules are still in the directory /opt/so/rules/elastalert/playbook/
Nothing is backed up
I have now manually backed up to /nsm/backup/detections-migration/sigma/rules/ and deleted all rules from /opt/so/rules/elastalert/playbook/ . I will check if the alerts come back