Merge pull request #15974 from Security-Onion-Solutions/jertel/wip

es|ql defaults
This commit is contained in:
Jason Ertel
2026-06-16 14:27:54 -04:00
committed by GitHub
2 changed files with 6 additions and 0 deletions
+1
View File
@@ -1464,6 +1464,7 @@ soc:
sigmaRulePackages:
- core
- emerging_threats_addon
useEsql: false
elastic:
hostUrl:
remoteHostUrls: []
+5
View File
@@ -383,6 +383,11 @@ soc:
global: True
advanced: False
helpLink: sigma
useEsql:
description: "(Pre-release) Use Elasticsearch Piped Query Language (ES|QL) instead of EQL (Elastic Query Language) for Elasticsearch queries. The Sigma converter will output ES|QL instead of EQL, allowing support for correlations."
global: True
advanced: True
forcedType: bool
elastic:
index:
description: Comma-separated list of indices or index patterns (wildcard "*" supported) that SOC will search for records.