airbus-cyber / graylog-plugin-alert-wizard

Alert Wizard plugin for Graylog to manage the alert rules
Other
46 stars 7 forks source link

Add compatibility with Graylog 3.2 #16

Closed TiNico22 closed 4 years ago

TiNico22 commented 4 years ago

Add compatibility with Graylog 3.2 Replace #11 we plan to support 3.2 directly instead

dio99 commented 4 years ago

hello just wonder if u done some work in this to get it working in 3.2 ? nice plugin u done

dio99 commented 4 years ago

is this plugin able to do a alert like this ?

(event_id:4625 AND keywords:"Audit Failure")

Threshold = 6 matches within 5min)

AND

(event_id:4624 AND keywords:"Audit Success")

Threshold = 1 match within 5min)

Alarm will be created when there will be at least 6 failed logon attempts and one successful logon within 5 min time span

tomasnk commented 4 years ago

Release 3.2.0 is compatible with Graylog 3.2