Detections- Unable to add a Sigma rule receive a 400 error #13228
Replies: 3 comments
-
Please provide the technical detail that is outlined here: #1720 |
Beta Was this translation helpful? Give feedback.
-
Security Onion version as seen in the lower left corner of SOC and in /etc/soversion. 2.4.70. |
Beta Was this translation helpful? Give feedback.
-
2.4.80 was released yesterday and has a number of fixes for Detections. I would suggest upgrading and seeing if that fixes the issue. As part of this release, there are new Detection templates. I would suggest editing the Sigma template so that you know you have the correct syntax. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
We are using Security Onion version 2.4.6, When trying to upload custom Sigma rules under Detections, we receive a 400 error. When trying to convert Sigma rules we receive a 500 error.
Beta Was this translation helpful? Give feedback.
All reactions