-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Aggregation issues with TheHive alerting #2560
Comments
In elastalert logs, I can see that all aggregation alerts are not sent to TheHive.
|
You can try it using this tag https://github.com/agix/elastalert/releases/tag/v0.2.1-agix-2
|
And how looks like the alert with your version @agix? |
yep
Le lun. 18 nov. 2019 à 11:22, emixam3 <[email protected]> a écrit :
… You can try it using this tag
https://github.com/agix/elastalert/releases/tag/v0.2.1-agix-2
pip install ***@***.***
And how looks like the alert with your version @agix
<https://github.com/agix>?
Like in #2263 <#2263>, without
hive description field?
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#2560?email_source=notifications&email_token=AATQCH6HGZPTXFPZVJWKM7TQUJUFHA5CNFSM4JMBHSTKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEEJ6HUA#issuecomment-554951632>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AATQCHZTEVDG7O6T6TXYGB3QUJUFHANCNFSM4JMBHSTA>
.
|
Ok, work in progress... |
Find : use alert_subject and alert_subject_args, and not alert's title. |
Hi,
I'm trying to use Elastalert to request Suricata alerts in my Elastic to send alerts to TheHive. Standards requests and alerts worked fine, and I've got all my Suricata alerts in TheHive.
But now I'm trying to aggregate these alerts (195 alerts) by signature's names (14 differents names).
This is my rule:
Even with my 10 minutes aggregation time, all my 195 alerts are sent every 2 minutes (my request time). With --verbose, I see all aggregations ID and some adding in, so I think aggregation is quite good, but not alerting in TheHive.
Thanks
The text was updated successfully, but these errors were encountered: