admin:add_alert_bash
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
admin:add_alert_bash [2024/04/29 13:35] – veera | admin:add_alert_bash [2024/04/29 13:57] (current) – veera | ||
---|---|---|---|
Line 2: | Line 2: | ||
- | On Ubuntu , the Trisul | + | On Ubuntu , the Trisul dispatcher reads from / |
+ | |||
+ | It then formats and pushes to | ||
+ | |||
+ | - Microsoft Teams via WebHooks | ||
Line 15: | Line 19: | ||
</ | </ | ||
+ | |||
+ | The fields are | ||
+ | * Alert: | ||
+ | * Timestamp tv_sec | ||
+ | * Timestamp tv_usec | ||
+ | * Source IP | ||
+ | * Port | ||
+ | * Dest IP | ||
+ | * Port | ||
+ | * SigID -- short name for alert | ||
+ | * Message | ||
+ | |||
+ | |||
+ | |||
admin/add_alert_bash.1714377904.txt.gz · Last modified: 2024/04/29 13:35 by veera