Merge pull request #12640 from Security-Onion-Solutions/cogburn/sigma-repo-support

Update ElastAlert Config with Default Repos
This commit is contained in:
coreyogburn
2024-03-22 14:24:18 -06:00
committed by GitHub

View File

@@ -1186,6 +1186,10 @@ soc:
denyRegex: ''
elastAlertRulesFolder: /opt/sensoroni/elastalert
rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint
rulesRepos:
- repo: https://github.com/Security-Onion-Solutions/securityonion-resources
license: DRL
folder: sigma/stable
sigmaRulePackages:
- core
- emerging_threats_addon