You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
Hi, I am trying to follow the tutorial from the documentation hub using an ELK stack. However, I am getting a KestrelSyntaxError when querying. I tried it with Python 3.6 and 3.9; both have the same error results.
Details of the bug
What is the hunt flow/script you are executing?
Hunt flow from the tutorial.
What is the command that failed?
var = GET process FROM stixshifter://host101
What is the error message?
[ERROR] KestrelSyntaxError: invalid token "" at line 1 column 24. rewrite the failed statement.
You may want to try with a WHERE clause to describe the processes you'd like to get. And for the first GET to a data source, we strongly recommend to add START/STOP. More information is in the syntax doc: https://kestrel.readthedocs.io/en/latest/language.html#get
Describe the bug
Hi, I am trying to follow the tutorial from the documentation hub using an ELK stack. However, I am getting a KestrelSyntaxError when querying. I tried it with Python 3.6 and 3.9; both have the same error results.
Details of the bug
Hunt flow from the tutorial.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Results from query
Environment (please complete the following information):
The text was updated successfully, but these errors were encountered: