sigma rules #1954
Unanswered
splunk-user1
asked this question in
Q&A, quick solutions, support
sigma rules
#1954
Replies: 1 comment 2 replies
-
can you post an file listing of Also note that it is currently not recommended to just clone all upstream sigma rules. This will cause performance issues and a lot of rules do simply not work. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
As suggested in the how-to document, I cloned sigma rules on the host at location
/opt/timesketch/data/
Q: how would it get replicated to
celery worker and webserver
docker containersSIGMA_RULES_FOLDERS = ['/etc/timesketch/sigma/rules/']
? Which shows default ruleSuspicious Installation of Zenmap
saved in the above path of both the containers. ThanksBeta Was this translation helpful? Give feedback.
All reactions