For example, over 4000 events per day should have an email notification.
If you are using Open Distro, where no CCS is being used and want to create an email notification for over 4000 events in a day, find below the high level steps:
Define using visual graph
, under Index enter wazuh-alerts*
(this will select all events that you visualize under Wazuh>Modules>Security Events), under Time field you can select @timestamp
. Leave the WHEN Count()
, OVER all documents
and WHERE all fields are included
as default, in option FOR THE LAST …
select for the last 24 hours
. Finally select the frequency under Monitor Schedule as Daily
and the time when you want this to run, alternatively you can select By interval
and run it Every 1 Days
, click on CreateIS ABOVE 4,000
. Under Configure actions select the Destination created in step 2, then the Message subject you would like the recipient to receive and you can leave the Message by default, it uses Mustache if you would like to edit it, you can send a test message to check if the Destination and smtp is configured correctly. Click on CreateI hope you are able to configure it, let me know!
The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.