Skip to content

Awarz 650 elastalert rules#664

Closed
aarz-snl wants to merge 7 commits intodevelopfrom
awarz-650-elastalert-rules
Closed

Awarz 650 elastalert rules#664
aarz-snl wants to merge 7 commits intodevelopfrom
awarz-650-elastalert-rules

Conversation

@aarz-snl
Copy link
Collaborator

@aarz-snl aarz-snl commented May 7, 2025

🗣 Description

#650

💭 Motivation and context

One elastalert rule that monitors Kibana alert index.

🧪 Testing

Install LME, turn on Windows Alerts in kibana security, setup the ElastAlert rule, trigger an alert (event log cleared)

See included .md file for directions

✅ Pre-approval checklist

  • Changes are limited to a single goal AND
    the title reflects this in a clear human readable format
  • Issue that this PR solves has been selected in the Development section
  • I have read and agree to LME's CONTRIBUTING.md document.
  • The PR adheres to LME's requirements in RELEASES.md
  • These code changes follow cisagov code standards.
  • All relevant repo and/or project documentation has been updated to reflect the changes in this PR.

✅ Pre-merge Checklist

  • All tests pass
  • PR has been tested and the documentation for testing is above
  • Squash and merge all commits into one PR level commit

✅ Post-merge Checklist

  • Delete the branch to keep down number of branches

@github-project-automation github-project-automation bot moved this to 🆕 Product Backlog in LME-Development May 7, 2025
@aarz-snl aarz-snl changed the base branch from main to develop May 7, 2025 19:36
@aarz-snl aarz-snl closed this May 8, 2025
@github-project-automation github-project-automation bot moved this from 🆕 Product Backlog to ✅ Done in LME-Development May 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

1 participant