-
Notifications
You must be signed in to change notification settings - Fork 564
How do I import the rules into Kibana? #656
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hey @avi8892 - How are you trying to import the rules? Via the CLI? Kibana requires a |
Thanks man!, can you please send me the command that shows how to convert the rules from tmol to ndjson? |
@avi8892 Here's the full CLI documentation - https://github.com/elastic/detection-rules/blob/main/CLI.md |
Can you help me with it? no matter what I do it always asking for kibana url. |
Hello @avi8892, there was a bug for a bit but has since been resolved. Ensure you are up to date with main and hopefully that resolves it |
Hi everybody, I have the same error :( , like @avi8892 |
@V1D1AN it is not fixed even I did what was recommended. |
So it actually is likely not a bug at all but an issue with how you are calling the command. It may be a bit subtle, but if you see under https://github.com/elastic/detection-rules/blob/main/CLI.md#commands-using-elasticsearch-and-kibana-clients, it shows that for commands under the client groups (
So just shift all of your client args to before |
Thanks for your help.
|
Why is it trying to access this URL? @brokensound77 |
I have the same error with ELK 7.10.1 , not the version 7.9.2 |
I'm on 7.10 :( |
@V1D1AN Sad, I have already installed winlogbeat and everything :/ |
Someone has already succeeded in importing rules into kibana ? you need another license than the "BASIC" license. |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
Hi guys, I'm trying to import the rules into Kibana but I can't. Can anyone help me with that?
The text was updated successfully, but these errors were encountered: