Hello SO-Team,
I have set up a new parallel SecurityOnion installation with ELK stack. (securityonion-16.04.4.2.iso)
The Squert Priority Filter shows a different behavior than in the productive SecurityOnion installation (securityonion-14.04). No events are assigned to the filter categories "high", "medium" or "low". Only the filter category "other" contains events.