Skip to content
Discussion options

You must be logged in to vote

Playbook allows you to easily create new detections which generate alerts in Security Onion. It uses ElastAlert in the background.

Playbook docs: https://docs.securityonion.net/en/2.3/playbook.html#creating-a-new-play

Security Onion Essentials training session that highlights Playbook: https://www.youtube.com/watch?v=IS2SOlDedPc&list=PLljFlTO9rB155aYBjHw2InKkSMLuhWpxH&index=7

If you all can give an example of what you are trying to do, I can show you how to do that within Playbook.

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@jtrodriguez
Comment options

@jtrodriguez
Comment options

Answer selected by weslambert
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants