Skip to content
Discussion options

You must be logged in to vote

We use the official pySigma converter with the elasticsearch-backend. (https://github.com/SigmaHQ/pySigma-backend-elasticsearch)

You probably want to look over our pipeline: https://github.com/Security-Onion-Solutions/securityonion/blob/3/main/salt/soc/files/soc/sigma_so_pipeline.yaml

There are certain places where we convert to a datatype to make sure it is compatible with how we ingest logs, for example: https://github.com/Security-Onion-Solutions/securityonion/blob/3/main/salt/soc/files/soc/sigma_so_pipeline.yaml#L235

Can you give me an example Sigma rule that uses event_type_id in the way that you describe?

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
3.0
Labels
None yet
2 participants