Skip to content
Discussion options

You must be logged in to vote

Hi @robbiemarshall, thanks for the reply.

I think I may have figured out what I was doing wrong. I missed the part about adding the "sofilter" filter to the "Custom Filter" field. I was adding it directly to the sigma. I've updated a few rules and now see them in the ElastAlert config. Hopefully it will be reflected in my actual SO alerts. I'll reply with an update in either scenario. Thanks again.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@kingtriumph
Comment options

Answer selected by kingtriumph
@kingtriumph
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants