Feature - auto-enabled Sigma rules

This commit is contained in:
DefensiveDepth
2024-04-03 08:21:50 -04:00
parent 7f488422b0
commit a8f25150f6

View File

@@ -1216,6 +1216,10 @@ soc:
elastalertengine:
allowRegex: ''
autoUpdateEnabled: true
autoEnabledSigmaRules:
- core+critical
- securityonion-resources+critical
- securityonion-resources+high
communityRulesImportFrequencySeconds: 86400
denyRegex: ''
elastAlertRulesFolder: /opt/sensoroni/elastalert