I’ve been trying to figure out if there is a way to create a stream rule based on a string within the message body.
I’ve looked through the internet and haven’t been able to find anything.
I’m able to sort my results on the elastic search with wildcard within the message body however for stream rule it appears to be a different set of rules.
I have snort setup to pipe information to our graylog and ultimately I would like to set email alerts on certain information coming from snort.
Please help. thanks.