Skip to content

Commit

Permalink
allow elastalert to query across clusters
Browse files Browse the repository at this point in the history
  • Loading branch information
weslambert committed Jan 4, 2018
1 parent a5675a3 commit 0d9ff75
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion etc/elastalert/rules/bro_conn.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ type: frequency

# (Required)
# Index to search, wildcard supported
index: logstash-bro*
index: "*:logstash-bro*"

use_strftime_index: true

Expand Down
2 changes: 1 addition & 1 deletion etc/elastalert/rules/ids.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ es_host: elasticsearch
es_port: 9200
name: Security Onion ElastAlert - New IDS Event!
type: frequency
index: logstash-ids*
index: "*:logstash-ids*"
num_events: 1
timeframe:
minutes: 1
Expand Down

0 comments on commit 0d9ff75

Please sign in to comment.