Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.4.tar.gz (16.7 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.4.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.4.tar.gz
Algorithm Hash digest
SHA256 d7256103e718fa993cf3e749972d7ce5d3405b8aead0d96c11487549d8eb6edc
MD5 7c1dce77a374842a9a6a876bf1786701
BLAKE2b-256 49819fded860c2fd52e2744b2b823fa917a93b13b4cc42caa6100b0655d7c36b

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.4-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.4-py3-none-any.whl
Algorithm Hash digest
SHA256 f87426131ad5948ced6ab7efa980d5b318e66196bb2932961e04df23479dccb5
MD5 ba9ad7b0e5fbfceff652aeeb40c508ea
BLAKE2b-256 df1fe53469fe1966662f9a133518d4c488821c7fc7d126c671d0cb20bb556d87

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page