Skip to content
Discussion options

You must be logged in to vote

@SimonCampbell85 I have communicated about this situation with the Sigma devs. We agree that this rule is broken. What's happening is that because it is not specifying a Logsource to map to a particular field, the Elastalert rule is searching for the strings in all the fields. This creates some problems - what you are seeing as well as performance issues etc.

I would suggest disabling this rule for now. It is in the process of being fixed.

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@SimonCampbell85
Comment options

Answer selected by defensivedepth
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants