Created on 04-18-2018 06:52 PM - edited 08-17-2019 07:24 PM
Hi, the metron alert ui is showing alerts coming from squid and snort. However, the problem is it can't trigger actions (Open/Dismiss/Escalation/Resolve) with an (any) alert. When I click on the button "Actions"->Some_Action (eg.: "Open"), the ui sends a POST request to http://alert_ui_server/search/_bulk (the attached images have more details) and the server returns 404 (not found). It's happening for all alerts.
Any idea what is wrong?