Question about rule #203
-
I am trying to use ElastAlert with Suricata. My filter is currently like this.
I am not getting any hits though. I suspect that I have to put the exact value of "suricata.eve.alert.signature". But what I want to do is to alert on any log that contains the words ET MALWARE, independent of what type of ET MALWARE alert it is |
Beta Was this translation helpful? Give feedback.
Answered by
ferozsalam
May 31, 2021
Replies: 1 comment 9 replies
-
Are you able to post the sort of document you expect to match against? Feel free to redact anything specific to your organisation. |
Beta Was this translation helpful? Give feedback.
9 replies
Answer selected by
jertel
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Are you able to post the sort of document you expect to match against? Feel free to redact anything specific to your organisation.