Alerts via syslogs #14303
Alerts via syslogs
#14303
Replies: 1 comment
-
If you want alerts to trigger from the contents of your firewall logs, you'll need to write or enable Sigma rules in Detections to spot the items that should trigger an alert. Most of the default alerting rules are in Suricata, which assumes that you're monitoring live network traffic, not simply ingesting logs. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I have security onion setup where I have my firewall syslogs coming to it. Do I have to do anything special for the alerts to trigger? I just find it odd nothing has alerted yet, considering where a university. Epically, since students visit some questionable sites sometimes. Any insights or help is much appreciated.
Beta Was this translation helpful? Give feedback.
All reactions