admin:add_alert_bash
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| admin:add_alert_bash [2024/04/29 13:34] – created veera | admin:add_alert_bash [2024/04/29 13:57] (current) – veera | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| - | On Ubuntu , the Trisul | + | On Ubuntu , the Trisul dispatcher reads from / |
| + | |||
| + | It then formats and pushes to | ||
| + | |||
| + | - Microsoft Teams via WebHooks | ||
| If you push a syslog message in the following format into syslog it will make to the automatic email alert delivery system. | If you push a syslog message in the following format into syslog it will make to the automatic email alert delivery system. | ||
| + | |||
| + | ''" | ||
| + | '' | ||
| < | < | ||
| Line 12: | Line 19: | ||
| </ | </ | ||
| + | |||
| + | The fields are | ||
| + | * Alert: | ||
| + | * Timestamp tv_sec | ||
| + | * Timestamp tv_usec | ||
| + | * Source IP | ||
| + | * Port | ||
| + | * Dest IP | ||
| + | * Port | ||
| + | * SigID -- short name for alert | ||
| + | * Message | ||
| + | |||
| + | |||
| + | |||
admin/add_alert_bash.1714377878.txt.gz · Last modified: 2024/04/29 13:34 by veera