SIGMA Correlation Rule - No generated events #14589
-
Version2.4.140 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationairgap Hardware SpecsExceeds minimum requirements CPU16 RAM32 Storage for /400 Storage for /nsm600 Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI am trying to create a brute force attack sigma rule through correlation which is aligned with default sigma rule "Security Onion - SOC Login Failure". the issue is that brute force rule doesn't generate alerts. however, through testing, the default rule generates failed login alerts. Here is the correlation rule:title: brute force - 3 login failed or more logsource: detection: falsepositives:
Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
I am looking forward to getting the first response of my question! |
Beta Was this translation helpful? Give feedback.
The "correlation" syntax that you're using in this rule is not supported in Security Onion.