Skip to main content

pySigma Elasticsearch backend

Project description

Tests Coverage Badge Status

pySigma Elasticsearch Backend

This is the Elasticsearch backend for pySigma. It provides the package sigma.backends.elasticsearch with the LuceneBackend class.

It supports the following output formats:

  • default: Lucene queries.
  • dsl_lucene: DSL with embedded Lucene queries.
  • kibana_ndjson: Kibana NDJSON with Lucene queries.

Further, it contains the following processing pipelines in sigma.pipelines.elasticsearch:

  • ecs_windows in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat.
  • ecs_windows_old in windows submodule: ECS mapping for Windows event logs ingested with Winlogbeat <= 6.x.
  • ecs_zeek_beats in zeek submodule: Zeek ECS mapping from Elastic.
  • ecs_zeek_corelight in zeek submodule: Zeek ECS mapping from Corelight.
  • zeek_raw in zeek submodule: Zeek raw JSON log field naming.

This backend is currently maintained by:

Further maintainers required! Send a message to Thomas if you want to co-maintain this backend.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_elasticsearch-1.0.9.tar.gz (18.1 kB view details)

Uploaded Source

Built Distribution

File details

Details for the file pysigma_backend_elasticsearch-1.0.9.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.9.tar.gz
Algorithm Hash digest
SHA256 dbddfe6f09ee1152c4d49c0fa1db839bcfc206267855b8aa4551384b40cd71a4
MD5 462aeb7f61a3ba7921be1dbe8b4e8c2b
BLAKE2b-256 2225c00046a3752853cf3836e1265d865b4f72d075261406f98698416f90b551

See more details on using hashes here.

File details

Details for the file pysigma_backend_elasticsearch-1.0.9-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_elasticsearch-1.0.9-py3-none-any.whl
Algorithm Hash digest
SHA256 dad15ae8710b44107959dd73a8ce3329a505e643b9fd3613649669d8aa3bc062
MD5 ba26290bdbca3ea77823cf5eb445cc5c
BLAKE2b-256 afd30e8d845bdb7011e9ad15c028aa93a3f91291c4c1d431b96ce51f5e6bfe21

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page