No alerts in the Hive.... #1641
-
|
Alerts will populate in the SOC's new alert tab but not in Hive. This is a airgaped distributed setup with one manager, two search nodes, and two fwd nodes. After activating all 492 sigma rules I still see no alerts in The Hive. I even downloaded a reverse meterpreter shell and executed malicious commands to populate alerts, still no luck. Any thoughts? This is a 2.3.1 build. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
|
Hi @ColeVan , Yes, this is expected behavior. From https://docs.securityonion.net/en/2.3/release-notes.html#id3:
So starting in 2.3 GA, the new workflow is that alerts go to Alerts and then you can selectively choose important alerts to escalate to TheHive to create a case. For more information, please see https://docs.securityonion.net/en/2.3/hive.html#hive. |
Beta Was this translation helpful? Give feedback.

Hi @ColeVan ,
Yes, this is expected behavior. From https://docs.securityonion.net/en/2.3/release-notes.html#id3:
So starting in 2.3 GA, the new workflow is that alerts go to Alerts and then you can selectively choose important alerts to escalate to TheHive to create a case.
For more information, please see https://docs.securityonion.net/en/2.3/hive.html#hive.