Skip to content
Discussion options

You must be logged in to vote

Yes, so-playbook-reset will wipe it all, so don't do that unless you have backed up your custom Plays :)

The short version of how this all works:

When a Play is made Active the following happens: An ElastAlert rule is generated, based on the content of the Play, and copied over to the Elastalert rules folder /opt/so/rules/elastalert/playbook

When a Play is edited, the Elastalert rule file is updated as needed.

When a Play is made inactive, the Elastalert rule file is deleted from /opt/so/rules/elastalert/playbook.

Every 3 minutes, Elastalert processes the current files in /opt/so/rules/elastalert/playbook and generates alerts accordingly.

Sometimes things get out of sync - that's where so…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants