Skip to content
Discussion options

You must be logged in to vote

Try running sudo so-playbook-sync on the manager. If it errors there will be a 9 digit code directly above the "warning" statement. Go back into playbook and add a "rule id" filter. Paste that 9 digit code into the filter box and press apply. This should show a single rule. That rule will have a syntax error in it. If that doesn't work try deleting all the .yaml files in "/opt/so/rules/elastalert/playbook/". Then run the sudo so-playbook-sync. There is a third thing you can try, but I can't remember the exact command off the top of my head. It's a "so-playbook-" command and it recreates the play from the base sigma rule.

Background is that we have seen plays get written or updated with a …

Replies: 5 comments 3 replies

Comment options

You must be logged in to vote
2 replies
@mskarshinski
Comment options

@mskarshinski
Comment options

Answer selected by defensivedepth
Comment options

You must be logged in to vote
1 reply
@mskarshinski
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants