mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 07:15:27 +02:00
Compare commits
2
Commits
3/main
...
esql-fixes
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f3aa39c5a4 | ||
|
|
1fc5bb7afa |
No files matched your search
@@ -1465,6 +1465,7 @@ soc:
|
|||||||
- core
|
- core
|
||||||
- emerging_threats_addon
|
- emerging_threats_addon
|
||||||
useEsql: false
|
useEsql: false
|
||||||
|
esqlCaseInsensitive: true
|
||||||
elastic:
|
elastic:
|
||||||
hostUrl:
|
hostUrl:
|
||||||
remoteHostUrls: []
|
remoteHostUrls: []
|
||||||
|
|||||||
@@ -1,6 +1,31 @@
|
|||||||
name: Security Onion Baseline Pipeline
|
name: Security Onion Baseline Pipeline
|
||||||
priority: 90
|
priority: 90
|
||||||
transformations:
|
transformations:
|
||||||
|
# ES|QL scalar == returns null on multivalued fields; the
|
||||||
|
# backend reads this key and emits MV_INTERSECTS instead.
|
||||||
|
- id: declare_multivalue_fields
|
||||||
|
type: set_state
|
||||||
|
key: multivalue_fields
|
||||||
|
val:
|
||||||
|
- event.type
|
||||||
|
- event.action
|
||||||
|
- event.category
|
||||||
|
- tags
|
||||||
|
- process.args
|
||||||
|
- related.ip
|
||||||
|
- dns.resolved_ip
|
||||||
|
- id: esql_default_index
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val: .ds-logs-*
|
||||||
|
- id: esql_source_metadata
|
||||||
|
type: set_state
|
||||||
|
key: metadata
|
||||||
|
val: "_id, _index, _source"
|
||||||
|
- id: esql_source_keep
|
||||||
|
type: set_state
|
||||||
|
key: keep
|
||||||
|
val: "_id, _index, _source"
|
||||||
- id: baseline_field_name_mapping
|
- id: baseline_field_name_mapping
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
|
|||||||
@@ -396,6 +396,11 @@ soc:
|
|||||||
global: True
|
global: True
|
||||||
advanced: True
|
advanced: True
|
||||||
forcedType: bool
|
forcedType: bool
|
||||||
|
esqlCaseInsensitive:
|
||||||
|
description: "Match string values case-insensitively when converting Sigma rules. Applies to ES|QL only"
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: bool
|
||||||
elastic:
|
elastic:
|
||||||
index:
|
index:
|
||||||
description: Comma-separated list of indices or index patterns (wildcard "*" supported) that SOC will search for records.
|
description: Comma-separated list of indices or index patterns (wildcard "*" supported) that SOC will search for records.
|
||||||
|
|||||||
Reference in new issue
Block a user