Replies: 1 comment 4 replies
-
Can you explain a bit more what you mean? If you want to generate alerts for your windows event data you will need to enable or create sigma rules https://docs.securityonion.net/en/2.4/sigma.html |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi guys!
After your last help I managed to get events from Domain Controller.
Now I want to apply aggregation.
Please tell me how to see all the events that come to me in SO in Alerts?
In kibana and hunt I have a lot of events, but in Alerts not a single one on Windows.
How to make all Windows events in Alerts?
Beta Was this translation helpful? Give feedback.
All reactions