Skip to content
Discussion options

You must be logged in to vote

This is not currently possible in Detections because of Sigma and EQL/Lucene.

The good news is that the Sigma project has recently come out with support for more complex rules like this and it is supported in Elastic ES|QL. (Still very early support) There is no timeline at this point for when it will be supported in Security Onion.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants