Closed safiuddinr closed 3 weeks ago
Ideally we have the following out of this:
podman run --net=es_default -d --name elastalert --restart=always -v $(pwd)/elastalert.yaml:/opt/elastalert/config.yaml -v $(pwd)/rules:/opt/elastalert/rules docker.io/jertel/elastalert2 --verbose
Ideally we have the following out of this:
a. monitor elasticsearch detections b. monitor wazuh detections
a. email out detections trigger