Issue Adding Sigma Rules from Local Repo #13910
Unanswered
jstore-embers
asked this question in
2.4
Replies: 1 comment 6 replies
-
When you say That dir needs to be a git repo. You should be able to run |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Version
2.4.100
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
20
RAM
64 GB
Storage for /
2 TB
Storage for /nsm
12 TB
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I am trying to add a private sigma ruleset offered by the DFIR Report. I can use git to pull the repo down to /nsm/rules/detect-sigma/repos/dfir-report/ and I've configured the following line in the admin interface under rule repos according to the documentation here
{"community":true,"folder":"rules/rules/sigma","license":"Elastic-2.0","repo":"file:///nsm/rules/detect-sigma/repos/dfir-report"}
I think the above is correct (not sure what I should put for license, so I copied the option from the securityonion-resources repo. Note the full path to the rules root folder in my instance is /nsm/rules/detect-sigma/repos/dfir-report/rules/rules/sigma but there are several subfolders.
I'm wondering where I may find logs that are generated when doing a full-update on the elastalert rules from the detections interface or if there's anything obviously wrong with this config.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions