Playbook elastalert rules are not working after updating rules from sigma repo #5973
-
Hi I am new to security onion playbook feature. I am trying to update the Sigma rules. As per documentation it has referred sigma rules from https://github.com/Neo23x0/sigma/tree/master/rules. So I modified the URL. (Is this correct way?) In playbook.py there are few backend options used while converting. Does that need update? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
There is ongoing work around this feature - I will update this Discussion with more details once we have it figured out. |
Beta Was this translation helpful? Give feedback.
There is ongoing work around this feature - I will update this Discussion with more details once we have it figured out.