Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.5.tar.gz (16.7 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.5.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.5.tar.gz
Algorithm Hash digest
SHA256 0985cc3435716ed96355ab66850818a9e29fc8de935be882c630b72caedc0f87
MD5 ef6f6710f2ce57481f14b9cefbe2149d
BLAKE2b-256 b72cd48bedcff78ee0a72984e9d814d9e8fe74ae868ec264ea6c354f1e276528

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.5-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.5-py3-none-any.whl
Algorithm Hash digest
SHA256 e6dff7cdad47a848c1f95d42609334b7b6dec2fbc7f4b263576055ecdf0c2ae6
MD5 29debb24fe8c6971de9da64e3ec3bb31
BLAKE2b-256 09f7ef65d8ecbe5dda65d3dc89ee9e10528c1f596856fac5e5875c783777921b

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page