Assistance Needed: Sigma Detection and Playbook Customization in Security Onion 2.4.110 #13977
-
Hello everyone, I’m currently using Security Onion 2.4.110, and I’ve encountered a couple of issues while working with Sigma detection rules and playbooks. I’d appreciate your insights or guidance.
Any suggestions, documentation links, or best practices are highly welcome! Thank you in advance for your help! Best regards, |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Hello there - can you confirm what version you are on? Security Onion Playbook was deprecated & removed prior to 2.4.110. |
Beta Was this translation helpful? Give feedback.
-
I got my answer and it was a problem related to the condition (the selection). |
Beta Was this translation helpful? Give feedback.
I got my answer and it was a problem related to the condition (the selection).