airbus-cyber / graylog-plugin-alert-wizard

Alert Wizard plugin for Graylog to manage the alert rules
Other
45 stars 7 forks source link

Set a default value for the "match all/at least one rules" #85

Closed frantz45 closed 1 year ago

frantz45 commented 2 years ago

This setting allows to choose if logs must match ALL rules defined or AT LEAST one rule. This setting is mandatory so default value should be set. The value "match all" seems fine.

It should also be set in the 2nd block of conditions for rules with multiple blocks (for example an "AND" rule).

frantz45 commented 1 year ago

@c8y3 I confirm it's fixed for the 1st block but not for the 2nd block (AND and THEN rule types), do you think it's another issue or do you want to fix it in this issue ?

c8y3 commented 1 year ago

Remove field title_condition.

frantz45 commented 1 year ago

I confirm it's fixed