Skip to content
Discussion options

You must be logged in to vote

There is a long history around this issue. We believe that case-insensitive, wildcard search capabilities are important - this used to be feasible with custom elasticsearch analyzers. With some technical changes to the underlying Elastic stack, this was no longer possible. So we moved to using EQL for the Sigma/Elastalert rules which allows wildcard + case insensitivity via the query language. OQL (based on lucene) has limited support for this, though we are working on finding a better solution.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@cmdpink
Comment options

@defensivedepth
Comment options

Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants