Error when applying IP filter to Sigma rules. #13527
Replies: 2 comments 3 replies
-
Can you share one of the actual alerts, so we can see what fields are included? |
Beta Was this translation helpful? Give feedback.
0 replies
-
This is one of the alerts. I would like to block 192.168.1.223 from triggering this. Security Onion IDH - SSH Accessed |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.90
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
4
RAM
32
Storage for /
200 gb
Storage for /nsm
150 gb
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I am trying to filter out my security scanner from triggering certain Sigma rules, however it seems the filter is breaking the rule. After applying the filter, the alert will not fire at all. I am also receiving an error when testing the filter in Kibana.

Am I applying this correctly?
Error when testing in Kibana.

Guidelines
Beta Was this translation helpful? Give feedback.
All reactions