Skip to content
Discussion options

You must be logged in to vote

Hi @ColeVan ,

Yes, this is expected behavior. From https://docs.securityonion.net/en/2.3/release-notes.html#id3:

We have a new Alerts interface for reviewing alerts and acknowledging or escalating them. Escalating creates a new case in TheHive. Please note that TheHive no longer receives alerts directly.

So starting in 2.3 GA, the new workflow is that alerts go to Alerts and then you can selectively choose important alerts to escalate to TheHive to create a case.

For more information, please see https://docs.securityonion.net/en/2.3/hive.html#hive.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@ColeVan
Comment options

@dougburks
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants