Is there some type of general Suricata rule for Elastic that will create a detection alert in Elastic SIEM everytime that the suricata rules goes off.
Related topics
Topic | Replies | Views | Activity | |
---|---|---|---|---|
Threat hunting with suricata, ElasticSecurity | 2 | 740 | June 14, 2021 | |
How to import suricate.rules into SIEM deteciton rules? | 2 | 48 | October 29, 2024 | |
Elastic Detection Rules | 1 | 226 | February 11, 2024 | |
Detection rules | 4 | 679 | January 11, 2021 | |
Issue with rules creation | 15 | 1717 | May 5, 2022 |