Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Running SIGMA from Kibana #571

Open
FrancescoFaenzi opened this issue Oct 5, 2021 · 0 comments
Open

Running SIGMA from Kibana #571

FrancescoFaenzi opened this issue Oct 5, 2021 · 0 comments

Comments

@FrancescoFaenzi
Copy link

Hello
I have a working HELK setup with Sigma.
I need to run all the SIGMA (stored in their HELK folder) at once on historical logs and then build dashboards etc on them.

I already tried sending those historical logs to HELK passing them via Winlogbeat etc and ElastAlert triggers correctly: unfortunately the timestamp of the ElastAlert-generated event is equal to SIGMA rule match time and does not equals original event timestamp.
Original event timestamp is written by ElastAlert in the field "match_body.event_original_time".

Is there any other way to do achieve the goal of setting this up?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant