Skip to content

Correlation rule #854

Locked Answered by jertel
praveens862 asked this question in Q&A
May 20, 2022 · 2 comments · 2 replies
Discussion options

You must be logged in to vote

You might be able to have a second rule that filters off of the elastalert_* indices and the suspicious activity. So only if both the blacklist rule was triggered recently and the suspicious activity occurred will it satisfy the rule query and trigger the alert. This is a much more advanced configuration so if you're new to ElastAlert 2, or don't have much experience exploring unfamiliar indices, like the ElastAlert 2 indices, then this may be too much to take on.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@praveens862
Comment options

@jertel
Comment options

Answer selected by jertel
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants