Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • eql: Elastic Event Query Language queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.10.tar.gz (18.7 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.10.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.10.tar.gz
Algorithm Hash digest
SHA256 cc9fbc131762152ad19fabf6b7e3fb8323b144c5a8843fc218461a9aac6859b2
MD5 80f221544b075c9fe1b7278c78ecee72
BLAKE2b-256 094ac01cb65dbe3c5ee43014f60784421254618bcfdb936ec004f46aa28a7a47

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.10-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.10-py3-none-any.whl
Algorithm Hash digest
SHA256 7fd36d643b1e56b338850af74a329b7bbbdeb91484135defb5dc51b3545826a5
MD5 be10e0e69df4cd0aefc0994bd126b767
BLAKE2b-256 c9e63a0b9429155f539bae79414c663ff011e4addab1b73219d6ec03f8a9ed6e

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page