NVISOsecurity / ee-outliers

Open-source framework to detect outliers in Elasticsearch events
https://blog.nviso.eu
GNU General Public License v3.0
203 stars 34 forks source link

Notifier TheHive #532

Open V1D1AN opened 4 years ago

V1D1AN commented 4 years ago

Hello, ee-outliers seems like a good project, do you plan to add "notifier" like "TheHive" or other ?? SMTP is only the possibility for the moment.

daanraman commented 4 years ago

Hi there,

Thanks for the question! At the moment, we only support mail indeed (in a very basic way) - internally, we also use The Hive with ee-outliers in the following way:

We wanted to keep the framework as agnostic of other tools as possible for now, so that's how we solve it ourselves internally - this ofcourse needs an integration with something like elastalert but we found that very simple to setup. Does this make sense for your use case?