Skip to content
Discussion options

You must be logged in to vote

It is a manual process - https://docs.securityonion.net/en/2.4/sigma.html#adding-new-sigma-rules Add a new play, your playbook should be in yaml format already, keep the unique UUID that is generated when the template is created, and paste your playbool yaml into the new play. Adjust wording as necessary.

For email alerting, that is done with the Pro feature notifications - https://docs.securityonion.net/en/2.4/notifications.html

Replies: 1 comment 9 replies

Comment options

You must be logged in to vote
9 replies
@nareshgarapati
Comment options

@cm-ops
Comment options

@nareshgarapati
Comment options

@cm-ops
Comment options

Answer selected by nareshgarapati
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants