Creating the SIEM Alert

Once the Command, Action, and Template are configured, the final step is to create the alert in the Pandora FMS SIEM engine. This alert “listens” for events occurring in the system and, if they match your filters, triggers the sending to MISP.

To begin, navigate to Management → Alerts → SIEM Alerts and click Create +. Then follow the 5-step wizard:


Step 1: Configure (Basic Settings)

Define the alert metadata:

image.png


Step 2: Conditions

image.png


Step 3: Filters (Detection Filters)

This step defines which SIEM events will trigger the alert and be sent to MISP. You can combine multiple fields for precise filtering:

For a standard integration, defining Severity and/or ID Rule is usually sufficient; other fields can remain empty or set to None.

image.png


Step 4: Fields (Additional Fields)

Select the template to apply to this alert. If the template contains custom fields (Macros _field1_, _field2_, etc.), their values are taken from the template. Typically, these fields already inherit configuration from the Command, Action, and Template, so they can be left as default.

image.png


Step 5: Triggering

Review the trigger summary:

image.png

Finalize the wizard to save the alert. Your integration is now fully operational in real-time, sending SIEM events to MISP automatically.


Revision #2
Created 6 March 2026 13:00:33 by Sergio Berruetta
Updated 6 March 2026 13:30:21 by Sergio Berruetta