Skip to content

Created new index pattern, alerts now not coming from new pattern #1399

Locked Answered by roman-tasi
roman-tasi asked this question in Q&A
Discussion options

You must be logged in to vote

Fixed it by cloning the winlogbeat template In index templates into a new sysmon template.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by roman-tasi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant