Skip to content
Discussion options

You must be logged in to vote

Our default settings for Elastic Agent generates/ships alot of logs:

  • Ships local system logs (syslog, Windows Eventlogs etc)
  • Generates logs for: process creation, network connections, registry changes, drivers loaded, etc

The detections that focus on these logsources are from Sigma rules loaded in Playbook. The vast majority of these are disabled by default, as they require a bit of tuning, field mapping changes and can cause performance issues if care is not taken to work through them.

The good news is that in our next release, we are debuting a brand new Detections module. It will replace Playbook. We will have a certain set of Sigma rules enabled and tuned by default. You can find ou…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
6 replies
@innovate-support
Comment options

@innovate-support
Comment options

@defensivedepth
Comment options

Answer selected by innovate-support
@innovate-support
Comment options

@dougburks
Comment options

@innovate-support
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants