Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New alarm: alarm_domainchange :bluecheck index alarm - any change of domain classification #129

Open
xychix opened this issue Nov 27, 2020 · 2 comments
Labels
alarm Related to RedELK alarms elkserver Related to RedELK server components enhancement New feature or request
Milestone

Comments

@xychix
Copy link
Collaborator

xychix commented Nov 27, 2020

I would like to see the following alarms added as part of alarm.py:

alarm for status change of domain classifications in bluecheck index. Alarm on any change!

@xychix xychix changed the title bluecheck index alarm New Alarm: bluecheck index alarm - any change of domain classification Nov 27, 2020
@xychix xychix changed the title New Alarm: bluecheck index alarm - any change of domain classification New Alarm - bluecheck index alarm - any change of domain classification Nov 27, 2020
@xychix xychix changed the title New Alarm - bluecheck index alarm - any change of domain classification New Alarm - alarm_domainchange :bluecheck index alarm - any change of domain classification Nov 27, 2020
@MarcOverIP
Copy link
Member

Should include a way to handle the situations where we are blocked by or get an error from one of the domain classifiers. For example, if the most recent check includes 'error', maybe wait an iteration and check if the error persists. If the error persists, also give an alarm to notify red team operators that the domain classification alarm isnt working anymore for that domain classifier. Same for 'Blocked'.

@fastlorenzo fastlorenzo added the enhancement New feature or request label May 14, 2021
@fastlorenzo fastlorenzo added elkserver Related to RedELK server components alarm Related to RedELK alarms labels May 27, 2021
@fastlorenzo fastlorenzo changed the title New Alarm - alarm_domainchange :bluecheck index alarm - any change of domain classification New Alarm: alarm_domainchange :bluecheck index alarm - any change of domain classification Nov 18, 2021
@fastlorenzo fastlorenzo changed the title New Alarm: alarm_domainchange :bluecheck index alarm - any change of domain classification New alarm: alarm_domainchange :bluecheck index alarm - any change of domain classification Nov 18, 2021
@MarcOverIP MarcOverIP added this to the v2.0.0-beta.6 milestone Jan 24, 2022
@MarcOverIP
Copy link
Member

After discussion with @fastlorenzo, decided that this first needs restructuring of how we handle domain info. So this is pending on #270

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
alarm Related to RedELK alarms elkserver Related to RedELK server components enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants