spcampbell/FireStic

Multiple alerts in one notification not handled

Closed this issue · 1 comments

When the root key is "alerts" instead of "alert" then FireEye is sending over multiple alert notifications embedded in one transaction. If the script cannot find "alert" it errors and continues. Need to look for both "alerts" and "alert" and handle both situations.

Have been running in prod for several weeks with no issues. Closing