Replies: 1 comment
-
Yes, so the short version is that this is a field mapping issue with some extra complexities. We are in the middle of fixing it and some others that have popped up. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.80
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
6
RAM
20 GO
Storage for /
400
Storage for /nsm
400
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Hello,
I've encountered an issue with the conversion of Sigma rules to EQL queries in Security Onion. The conversion does not seem to work correctly for a specific rule.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions