ELSA Queries in CIDR Notation

409 views
Skip to first unread message

LEON DINH

unread,
May 20, 2014, 2:40:21 PM5/20/14
to securit...@googlegroups.com
Hello,

I was wondering if it was possible to search for multiple IP ranges using ELSA, preferably in CIDR notation. I am working on setting up multiple alerts for various different subnets.

Thanks,

L.D.

Doug Burks

unread,
May 20, 2014, 11:47:04 PM5/20/14
to securit...@googlegroups.com
Hi Leon,

Please see:
https://groups.google.com/d/topic/enterprise-log-search-and-archive/X0qbDUt6XAw/discussion
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/d/optout.



--
Doug Burks

LEON DINH

unread,
May 21, 2014, 9:45:46 AM5/21/14
to securit...@googlegroups.com
Thanks for your response! I've tried using macros but seem to run into the same problem as before- I cannot search for more than one IP range in one query and get a "conflicting terms" error.

Doug Burks

unread,
May 26, 2014, 5:51:49 AM5/26/14
to securit...@googlegroups.com
My guess is that you're getting the "conflicting terms" error because
search terms are AND'd by default. Have you tried inserting an
explicit OR between search terms?

On Wed, May 21, 2014 at 9:45 AM, LEON DINH <ld...@wisc.edu> wrote:
> Thanks for your response! I've tried using macros but seem to run into the same problem as before- I cannot search for more than one IP range in one query and get a "conflicting terms" error.
>

chris izatt

unread,
Feb 17, 2017, 1:46:43 PM2/17/17
to security-onion, ld...@wisc.edu

I use something like this to search multiple subnets ("10.2.x.x" or "10.3.3.x")

Reply all
Reply to author
Forward
0 new messages