SELKS
SELKS copied to clipboard
SID Reference in eve.json in eve-box
how to add field Reference & link SID in .json field ?
for view in eve-box and send to SIEM .
Sample References Url: doc.emergingthreats.net/2001583
thanks for support ! Best Regard .
In the alerts you mean?
https://github.com/StamusNetworks/SELKS/issues/252#issuecomment-683667009
Yes
Hmmm ..not sure what the easiest would be - @jasonish any ideas besides enabling the rule dumping in the alert records ?
Hmmm ..not sure what the easiest would be - @jasonish any ideas besides enabling the rule dumping in the alert records ?
I don't think there is enough info in the rule itself, as a references.config is required... However, we can make some good guesses, at least with most ET rules, that I could present links to references in the EveBox UI.
Dear @pevma & @jasonish Thanks for support. Please advise to me for my issue. (#252) Best Regards.