Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.8.tar.gz (18.0 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.8.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.8.tar.gz
Algorithm Hash digest
SHA256 b2b4c29e3ab763ef39640225a1b5ad4a7892cb591366e87aa592ab34cf021f8b
MD5 77bf5b3f1c90bf97189badaa931c8d62
BLAKE2b-256 3977546ab82ff7fab17564af32ec5d288ae00236d0b87ec7d1692e71191b2b57

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.8-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.8-py3-none-any.whl
Algorithm Hash digest
SHA256 05b70163377b5d262ef852ed41db7ba1692d6083421a43187e5daae9f5b29792
MD5 5b329582a16c7cde80558891f89b2f4a
BLAKE2b-256 9321913d16bc51f09f6a4dcd80a02af1428f0701aa34280fc9dbd3ed6c6d4ed6

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page