diff --git a/salt/soctopus/files/templates/generic.template b/salt/soctopus/files/templates/generic.template index 992db3fa9..23b693258 100644 --- a/salt/soctopus/files/templates/generic.template +++ b/salt/soctopus/files/templates/generic.template @@ -3,20 +3,6 @@ {% set hivekey = salt['pillar.get']('static:hivekey', '') %} es_host: {{es}} es_port: 9200 -name: Alert-Name -type: frequency -index: "*:logstash-*" -num_events: 1 -timeframe: - minutes: 10 -buffer_time: - minutes: 10 -allow_buffer_time_overlap: true - -filter: -- query: - query_string: - query: 'select from test' alert: modules.so.thehive.TheHiveAlerter @@ -32,7 +18,7 @@ hive_alert_config: title: '{rule[name]}' type: 'external' source: 'SecurityOnion' - description: '`Data:` {match[message]}' + description: "`Play:` https://{{es}}/playbook/issues/6000 \n\n `Data:` {match[message]}" severity: 2 tags: ['elastalert', 'SecurityOnion'] tlp: 3