ElasAlert: Rule Mismatch Error After Upgrading to Security Onion 2.4.120 #14270
Replies: 1 comment
-
What kind of alerts were you seeing before that you're no longer seeing?
From https://docs.securityonion.net/en/2.4/detections.html#rule-engine-status: |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello everyone,
I recently upgraded Security Onion from version 2.4.11 to 2.4.120. After the upgrade, everything seemed to be working fine, but I wasn't seeing any alerts. To address this, I enabled all detection rules, and now I am seeing an error in the Detections section:
🔹 ElasAlert: Rule Mismatch Error
Here is my current setup:
✅ Distributed deployment with Search, Forward, and Receiver nodes, all connected to the Manager node
✅ All detection rules enabled
I’d really appreciate any guidance on how to resolve this ElasAlert: Rule Mismatch issue. Has anyone encountered this before? What troubleshooting steps should I follow to get the alerts working correctly?
Thanks in advance for your help! 🙌
Beta Was this translation helpful? Give feedback.
All reactions