Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there any way to edit max_query_size #537

Open
aniketpant1 opened this issue Jan 19, 2021 · 2 comments
Open

Is there any way to edit max_query_size #537

aniketpant1 opened this issue Jan 19, 2021 · 2 comments
Labels
custom build Using the HELK with settings that have not been tested or recommended yet

Comments

@aniketpant1
Copy link

In helk_elastalert there is a directory called rules there are 800 something rules i have to add max_query_size parameter is there any option to add the above parameter

@Cyb3rWard0g
Copy link
Owner

Hello @aniketpant1 , the rules are created automatically from SIGMA to elastalert. I do not know if it can be added when the rule is translated. I believe that would be a question to the SIGMA project. I do not know if that's what you mean (Adding the property to every single rule right?)

@Cyb3rWard0g Cyb3rWard0g added the custom build Using the HELK with settings that have not been tested or recommended yet label Feb 4, 2021
@aniketpant1
Copy link
Author

Yes but now i have stop using elastalert but i am going to restart this...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
custom build Using the HELK with settings that have not been tested or recommended yet
Projects
None yet
Development

No branches or pull requests

2 participants