Documentation for so-rule #3354
-
I like the addition of the so-rule script. I see in the documentation here: https://docs.securityonion.net/en/2.3/managing-alerts.html#so-rule you go over the so-rule method for disabling an SID, and give the example for manually modifying a SID. Is it possible to include an example of how you would use the new so-rule script to modify a SID? |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Mar 9, 2021
Replies: 1 comment 2 replies
-
I've updated the documentation to include an example of modifying a SID: |
Beta Was this translation helpful? Give feedback.
2 replies
Answer selected by
dougburks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
I've updated the documentation to include an example of modifying a SID:
https://docs.securityonion.net/en/2.3/managing-alerts.html#modify-the-sid