mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-06-16 23:30:42 +02:00
Compare commits
3 Commits
reyesj2/wip
...
3/dev
| Author | SHA1 | Date | |
|---|---|---|---|
| aa58225e8f | |||
| acf48db915 | |||
| ae1ddf3817 |
@@ -1464,6 +1464,7 @@ soc:
|
||||
sigmaRulePackages:
|
||||
- core
|
||||
- emerging_threats_addon
|
||||
useEsql: false
|
||||
elastic:
|
||||
hostUrl:
|
||||
remoteHostUrls: []
|
||||
|
||||
@@ -383,6 +383,11 @@ soc:
|
||||
global: True
|
||||
advanced: False
|
||||
helpLink: sigma
|
||||
useEsql:
|
||||
description: "(Pre-release) Use Elasticsearch Piped Query Language (ES|QL) instead of EQL (Elastic Query Language) for Elasticsearch queries. The Sigma converter will output ES|QL instead of EQL, allowing support for correlations."
|
||||
global: True
|
||||
advanced: True
|
||||
forcedType: bool
|
||||
elastic:
|
||||
index:
|
||||
description: Comma-separated list of indices or index patterns (wildcard "*" supported) that SOC will search for records.
|
||||
|
||||
Reference in New Issue
Block a user