Sigma Detections Filter #13272
-
Version2.4.80 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU8 RAM24 Storage for /100 Storage for /nsm100 Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI have a question about the new detections module.
How can I create a custom filter in the detections tab to filter, when this event has happend three times in one minute? I was trying like this, but when I convert it the message
Do I have to create a custom ElastAlert2 Config? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
This is not currently possible in Detections because of Sigma and EQL/Lucene. The good news is that the Sigma project has recently come out with support for more complex rules like this and it is supported in Elastic ES|QL. (Still very early support) There is no timeline at this point for when it will be supported in Security Onion. |
Beta Was this translation helpful? Give feedback.
This is not currently possible in Detections because of Sigma and EQL/Lucene.
The good news is that the Sigma project has recently come out with support for more complex rules like this and it is supported in Elastic ES|QL. (Still very early support) There is no timeline at this point for when it will be supported in Security Onion.