How to move my Playbooks to detections #15235
-
Version2.4.190 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationairgap Hardware SpecsMeets minimum requirements CPU4 RAM16 Storage for /250 Storage for /nsm50 Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailI upgraded distributed Airgap sec onion setup from version 2.4.2 to 2.4.190 . I understand that playbooks are moved to detections, How do i reinstate my playbook rules to detections, are they not migrated automatically. I dont see any alerts in my Dashboard after the upgrade. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 9 replies
-
|
How many playbook rules did you have? There was a migration in soup for 2.4.70. If you look in your |
Beta Was this translation helpful? Give feedback.

It is a manual process - https://docs.securityonion.net/en/2.4/sigma.html#adding-new-sigma-rules Add a new play, your playbook should be in yaml format already, keep the unique UUID that is generated when the template is created, and paste your playbool yaml into the new play. Adjust wording as necessary.
For email alerting, that is done with the Pro feature notifications - https://docs.securityonion.net/en/2.4/notifications.html