Sigma translation to ElastAlert problem #9344
-
Hi!
and it gets translated to the following ElastAlert query: Where is the "\" comming from? This breaks the query. Or what is wrong with my Sigma condition? Cheerss, Ben |
Beta Was this translation helpful? Give feedback.
Answered by
ben-sec
Dec 9, 2022
Replies: 1 comment
-
Hmm, now it's suddenly working. Ahh, it's working in Lucene syntax, but not in KQL (where I tried it before manually)! |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
ben-sec
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hmm, now it's suddenly working. Ahh, it's working in Lucene syntax, but not in KQL (where I tried it before manually)!