How to trigger an alert for sudo execution using detection tab #14066
Replies: 2 comments 8 replies
-
I tried to create a custom rule in /opt/so/rules/elastalert/rules/custom/custom_rulefailedlogin.yaml if i add this path in
|
Beta Was this translation helpful? Give feedback.
0 replies
-
What is the error for the Elastalert container? |
Beta Was this translation helpful? Give feedback.
8 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,

I have installed security onion 2.4 in Rocky Linux 9 with 4 vcpu and 16GB RAM and with 250 root volume. I have created a trigger to raise an alert whenever the sudo command is executed in endpoints where the agents is installed using playbook! and it was working. Now as the playbook was replaced with detection tab i have created same rule in detection tab but i'm not getting the alert why ?? still in the alert tab the alerts are coming from playbook
it have to give the alert if the rule got trigger in the endpoint where the elastic agent is installed
Beta Was this translation helpful? Give feedback.
All reactions