Wes
The error I was getting and still am is this.
/usr/sbin/so-elastalert-test: line 34: [: =: unary operator expected
This is a fully patched SO server.
The output from the run is as follows.
merlin@trinity-ids:/etc/elastalert/rules$ sudo so-elastalert-test
This script will allow you to test an elastalert rule.
Note: The rule must be accessable by the elastalert docker container.
Please enter the file path and rule name you want to test.
/etc/elastalert/rules/
bro_conn.yaml change.yaml flatline.yaml ids.yaml new_term.yaml trinity1.yaml
/etc/elastalert/rules/flatline.yaml
The results can be rather long. Would you like to write the results to a file? (Y/N)
/usr/sbin/so-elastalert-test: line 34: [: =: unary operator expected