Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.7.tar.gz (16.7 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.7.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.7.tar.gz
Algorithm Hash digest
SHA256 969199fb2d487cb961aebab1a8912fd26e3726dd4810f354c5c3f2d450a1a59a
MD5 0bccc6b352e048708d7ef4d09725b220
BLAKE2b-256 e879f437dd6333969052713bd1a846b312a6b4121a3318d45fea4e312ac3ca65

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.7-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.7-py3-none-any.whl
Algorithm Hash digest
SHA256 11eab7aa6901c01936fb8d30589ea759a5a2dcf40b9f001513112c8271569b3b
MD5 b060ee4beefde11c540f4820c2bf3cb3
BLAKE2b-256 098727fea19a3a5a4c66a829e556c2b127c2fe34b60bef6c2ef9072fa29248e8

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page