Sigma rules disappear after enabling #15453
Unanswered
gustavoberman
asked this question in
2.4
Replies: 1 comment 6 replies
-
|
Did you synchronize Elastalert after you enabled them? |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
Other (please provide detail below)
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
other (please provide detail below)
Hardware Specs
Meets minimum requirements
CPU
20
RAM
16GB
Storage for /
150GB
Storage for /nsm
300GB
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Hello there,
I started testing a standalone 2.4.201 ManagerSearch install for a small network.
Installation went without a problem, same with agent installation in 10 hosts between physical/virtual servers and physical desktops. All linux based
So I went to Detection, filter to include sigma, core, and then linux, this came up with some 26 rules.
I enabled all 26. I wait for some minutes, look for other things, when I came back to detections, this rules are nowhere. Not in enabled or disabled. Wait for a couple hours and the rules are still not there.
Next day, the rules appears again, enabled.
Any idea what causes this?
How can I follow the process?
/opt/so/log/elastalert/elastalert.log have a lot of errors regarding some of this enabled rules like:
And if I check for that rule in "convert" it gives me the following error in kibana:
Another example error is :
Which convert and test in kibana gives:
So I guess that there are a lot predefined sigma core rules that makes no sense and have to test each one before enabling
Thanks!
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions