Replies: 2 comments 7 replies
-
Hi, @Dunkaknee the alert has some issues, please read our documentation in -> https://docs.utmstack.com/Correlation%20Rules/README.html
Best regards |
Beta Was this translation helpful? Give feedback.
7 replies
-
Hi, @Dunkaknee, restart the instance and send logs, if not fixed try this, remove the rule from utmstack web app, then got to settings from lateral menu, then index management section, once there, remove all alert indexes, after that, create de rule again using the app. Let us know. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I am creating a Customizable Correlation rule to generate alerts whenever I receive logs from my Sentinel One integration for "Threat status changed" I can view the logs and when I filter by these fields the logs appear, but no alerts are generated
Here is my example Correlation Rule,
Below is an example Alert
@timestamp: "2024-12-17T16:21:17.286454752Z"
dataSource: "Hidden"
dataType: "antivirus-sentinel-one"
deviceTime: "2024-12-17T16:21:17.223610559Z"
host: "10.0.1.36"
id: "91935bed-208a-4e05-bea4-c24c25ce5a70"
logx:
sentinel_one:
accountId: "Hidden"
accountName: "Hidden"
act_msg: "Threat status changed"
activityID: "2107416621616565044"
activityType: "4008"
cat: "SystemEvent"
cef_version: "0"
deviceVersion: "S-24.2.6#171"
embDeviceProduct: "Mgmt"
embDeviceVendor: "SentinelOne"
fileHash: "ffffffffffffffffffffffffffffffffffffffff"
filePath: "/Volumes/test.pkg"
message: "<14>2024-12-17 16:21:17,212 sentinel - CEF:0|SentinelOne|Mgmt|S-24.2.6#171|4008|Threat status changed|1|osName=macOS fileHash=ffffffffffffffffffffffffffffffffffffffff filePath=/Volumes/test.pkg cat=SystemEvent rt=Tue, 17 Dec 2024, 16:20:38 UTC activityID=2107416621616565044 activityType=4008 siteId=Hidden siteName=Hidden accountId=Hidden accountName=Hidden notificationScope=SITE"
notificationScope: "SITE"
osName: "macOS"
rt: "Tue, 17 Dec 2024, 16:20:38 UTC"
severity: "1"
signatureID: "4008"
siteId: "Hidden"
siteName: "Hidden"
Beta Was this translation helpful? Give feedback.
All reactions