<
securit...@googlegroups.com> wrote:
>
> ________________________________
> From: Doug Burks <
doug....@gmail.com>
> To: "
securit...@googlegroups.com" <
securit...@googlegroups.com>
> Sent: Monday, May 26, 2014 3:01 AM
> Subject: Re: [security-onion] emails on the "High Severity" (red) alerts
>
> Hi Joseph,
>
> To clarify, /etc/nsm/securityonion/sguild.email is for Sguil, not
> Snorby. However, you can certainly use it to generate emails. Just
> remember that any changes to the file require a restart of the Sguil
> daemon:
>
> sudo nsm_server_ps-restart
>
>
>
> On Wed, May 21, 2014 at 5:45 PM, 'Joseph Spenner' via security-onion
> <
securit...@googlegroups.com> wrote:
>>
>> Hello, I'm curious if it's possible to configure Snorby such that it only
>> emails on the "High Severity" (red) alerts as displayed in the GUI?
>> I checked out the /etc/nsm/securityonion/sguild.email file, and saw the
>> option for EMAIL_CLASSES. I am guessing I could find all of those which
>> are
>> "High Severity". Is that the only way?
>
>
> Doug:
> Thanks for the reply!
> How would I modify the config to only email on the High Severity? Is this
> possible, without configuring for each possible alert?
>