Skip to content
Discussion options

You must be logged in to vote

To answer your summary questions.

  1. No, Elastic detection rule alerts will end up in .alerts-security.alerts-default with a Data View that is .alerts-security.alerts-default and Detections will look in logs-* You might be able to add the Data View here soc > config > server > modules > elastic > index [adv] for SOC to search for records.
  2. Sigma rules thresholds would be correlations, currently we don't support correlations, but it is on the roadmap.
  3. See 2
  4. We support using Detections.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@nayadmohamed
Comment options

Answer selected by nayadmohamed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants