pySigma Elasticsearch backend
Project description
pySigma Elasticsearch Backend
This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch
with the LuceneBackend
class.
It supports the following output formats:
- default: Lucene queries.
- dsl_lucene: DSL with embedded Lucene queries.
- kibana_ndjson: Kibana NDJSON with Lucene queries.
Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch
:
- ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
- ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
- ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
- ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
- zeek_raw in zeek submodule: Zeek raw JSON log field naming.
This backend is currently maintained by:
Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file pysigma_backend_elasticsearch-1.0.5.tar.gz
.
File metadata
- Download URL: pysigma_backend_elasticsearch-1.0.5.tar.gz
- Upload date:
- Size: 16.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.5.1 CPython/3.8.10 Linux/5.15.0-1040-azure
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 0985cc3435716ed96355ab66850818a9e29fc8de935be882c630b72caedc0f87 |
|
MD5 | ef6f6710f2ce57481f14b9cefbe2149d |
|
BLAKE2b-256 | b72cd48bedcff78ee0a72984e9d814d9e8fe74ae868ec264ea6c354f1e276528 |
File details
Details for the file pysigma_backend_elasticsearch-1.0.5-py3-none-any.whl
.
File metadata
- Download URL: pysigma_backend_elasticsearch-1.0.5-py3-none-any.whl
- Upload date:
- Size: 17.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.5.1 CPython/3.8.10 Linux/5.15.0-1040-azure
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | e6dff7cdad47a848c1f95d42609334b7b6dec2fbc7f4b263576055ecdf0c2ae6 |
|
MD5 | 29debb24fe8c6971de9da64e3ec3bb31 |
|
BLAKE2b-256 | 09f7ef65d8ecbe5dda65d3dc89ee9e10528c1f596856fac5e5875c783777921b |