Skip to content

Rules not visible in Threat Management #865

Closed Answered by c3s4rfred
Pelican9091 asked this question in Q&A
Discussion options

You must be logged in to vote

To check the rules, first you need to access to the web application, enable some integrations, then go to -> Log explorer menu and see if the logs are coming. Also you can access to your instance and see the logs of the
using 'docker ps and docker logs containerId' commands, if there aren't errors, everything is fine. Finally, the custom rules must match with the values coming from the logs. Check our documentation to see how rules works -> https://docs.utmstack.com/Correlation%20Rules/README.html

You can send generic logs via syslog or json to our platform, then you can create your own rules, but actually we don't have dedicated integrations for sysmon or suricata in v 10.x.x

Best regards

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Pelican9091
Comment options

@c3s4rfred
Comment options

Answer selected by c3s4rfred
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants