Skip to content

elastalert - email-notifications - debugging? #14451

Discussion options

You must be logged in to vote

Try placing your rule in /opt/so/rules/elastalert/rules/custom/

Then to manually run it with so-elastalert-test use

so-elastalert-test -r rules/custom/test.yml

Yes, logs-suricata.alerts-so is the correct index for looking at suricata alerts

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@reyesj2
Comment options

@ejgh-oe
Comment options

Answer selected by ejgh-oe
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants