Open priamai opened 3 years ago
With the help of the author I managed to replicate the docker container and add a few rules. Now the final challenge I believe is for each rule to match the template to avoid that error. I need to dig a bit more into the code.
I also found an interesting blog where they talk about the same issue:
"Unfortunately, this rule can’t be directly used by ( Praeco/Elastalert-Server ) because of several missing fields. So, you can pick the important information from this rule (the query string) and create your own rule in Praeco interface with this information. This tool is very important because it helps you to gather information about a lot of rules and their query strings. Note: Sometimes you have to check your logs in (Kibana → Discover Interface) and their fields to make sure that name fields in your logs match with name fields in sigma rules. If your fields show a yellow error, go to index pattern, choose the index to match and click refresh fields."
My aim now is to first generate the rules via sigma converter and then create templates via a script. The templates which are easier to generate can then be converted into rules.
Hi @neu5ron, I have an early xmas gift for you.
I will post my docker configuration on github and you can integrate into HELK. I can also try to integrate into HELK via merge request.
OHHHH OHHHHH OHHHHHHH
@priamai awesome! Do you have the configs to share?
@neu5ron fork here and working on this branch: https://github.com/priamai/HELK/tree/praeco
I will let you one you can test it.
I just found out during the integration test that Praeco webapp comes packaged with Nginx which is interfering with the HELK Nginx configuration. I have to find a way maybe to disable it and then apply the same config into HELK. Argh!
@neu5ron if you want to try this commit: I have added an option 3 for the new praeco setup. The praeco up fails to start:
Starting Nginx
nginx: [emerg] host not found in upstream "helk-elastalert-praeco" in /etc/nginx/conf.d/default.conf:11
Line 11:
proxy_pass http://helk-elastalert-praeco:3030/;
I am not sure why it is unable to find the host which I have defined in the corresponding docker compoese file with the proper dependencies.
Problem solved: I missed the network config in the docker composer file and now is all working. Last step is to add the rules conversion and we should be ready.
By the way this is a POC to show that the configuration (outside HELK) with praeco is working: https://gitlab.com/priampraeco/praecoes7/-/tree/master Good for testing or educational purposes.
By the way this is a POC to show that the configuration (outside HELK) with praeco is working: https://gitlab.com/priampraeco/praecoes7/-/tree/master Good for testing or educational purposes.
I got curious and wanted to see what it is, but unfortunately, it needs some modification since it doesn't work out of the box
By the way this is a POC to show that the configuration (outside HELK) with praeco is working: https://gitlab.com/priampraeco/praecoes7/-/tree/master Good for testing or educational purposes.
I got curious and wanted to see what it is, but unfortunately, it needs some modification since it doesn't work out of the box
Can you describe the issue and attach here the relevant logs ?
Hi @neu5ron, I have completed the branch and you can now test it: https://github.com/priamai/HELK/tree/praeco it was also very simple to rename the HELK rules. There are a few things to notice:
Feel free to reach me out here on in private if you have any issues merging/testing. Cheers.
elastalert has really died - @priamai have you found a fork/branch of elastalert?
Hi there, is anybody working on adding Praeco to manage and visualize the Alert rules? There is a full docker configuration here: https://github.com/johnsusek/praeco My understanding is that you can simply add the web app into the docker composer file and point it to the ElasticSearch server.