Observables for TheHive #248
-
I have the rule already created, but it doesn't send me any observable no and I don't know what the problem is, the alert is created but without any observable.
The dissect.alert, is a field created with the dissect option of filebeat. Thanks for reading :) |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 21 replies
-
It looks like you're using the old-style TheHive alerter syntax. Which version of ElastAlert are you using? If you're using the latest version of ElastAlert, you need to use the syntax described in the documentation here: https://elastalert2.readthedocs.io/en/latest/ruletypes.html#thehive |
Beta Was this translation helpful? Give feedback.
It looks like you're using the old-style TheHive alerter syntax. Which version of ElastAlert are you using? If you're using the latest version of ElastAlert, you need to use the syntax described in the documentation here: https://elastalert2.readthedocs.io/en/latest/ruletypes.html#thehive