Replies: 4 comments
-
This is a pro feature. You can contact support if you have pro and they can assist in taking a look at this. If you do not own pro you will have to manage Elastalert rules and alerters via the cli by dropping your elastalert rules in Please note that this is the exact same way it was done prior to 2.4.70. |
Beta Was this translation helpful? Give feedback.
-
Thank you for the clarification. Do you have a sample custom rule or documentation that I can refer to? |
Beta Was this translation helpful? Give feedback.
-
Anyone? I have been struggling to get the rule to work. |
Beta Was this translation helpful? Give feedback.
-
https://docs.securityonion.net/en/2.4/elastalert.html https://elastalert2.readthedocs.io/en/latest/elastalert.html#overview |
Beta Was this translation helpful? Give feedback.
-
Version
2.4.100
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
4
RAM
32
Storage for /
293GB
Storage for /nsm
700G
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
No email alerts from elastalert.
Steps I have taken:
I have tried with and without email authentication.
Did I miss a step?
Please advise. Thank you.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions