Skip to content
Discussion options

You must be logged in to vote

all the rules are still in the directory /opt/so/rules/elastalert/playbook/

Nothing is backed up

I have now manually backed up to /nsm/backup/detections-migration/sigma/rules/ and deleted all rules from /opt/so/rules/elastalert/playbook/ . I will check if the alerts come back

Replies: 4 comments 25 replies

Comment options

You must be logged in to vote
8 replies
@sleepingbel
Comment options

@defensivedepth
Comment options

@sleepingbel
Comment options

Answer selected by defensivedepth
@defensivedepth
Comment options

@sleepingbel
Comment options

@sleepingbel
Comment options

@defensivedepth
Comment options

Comment options

You must be logged in to vote
10 replies
@defensivedepth
Comment options

@sleepingbel
Comment options

@sleepingbel
Comment options

@defensivedepth
Comment options

@defensivedepth
Comment options

Comment options

You must be logged in to vote
1 reply
@defensivedepth
Comment options

Comment options

You must be logged in to vote
6 replies
@defensivedepth
Comment options

@defensivedepth
Comment options

@sleepingbel
Comment options

@sleepingbel
Comment options

@defensivedepth
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants