Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Increase rule level #1377

Open
mirawara opened this issue Jun 4, 2024 · 0 comments
Open

Increase rule level #1377

mirawara opened this issue Jun 4, 2024 · 0 comments

Comments

@mirawara
Copy link

mirawara commented Jun 4, 2024

Hello,
I have installed wazuh docker multi-node following this guide https://documentation.wazuh.com/current/deployment-options/docker/wazuh-container.html
and I have correctly configured the alert notifications via email. However, I have a problem. I would like to keep the alerts at level 12 but receive an alert when Clamav detects a virus. If I map in the worker and master containers the file /var/ossec/ruleset/rules/0320-clam_av_rules.xml with the modified level, the rule is no longer triggered and I see nothing even in the Security Event section of the agent. If instead I follow this guide: https://documentation.wazuh.com/current/user-manual/ruleset/rules/custom.html, the rule is triggered but it remains at level 8. From the GUI I can correctly see the modified rules (in the first case) or added (in the second). How can I solve this? Can anyone help me?
Thanks in advance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant