Elastalert Backend #220
-
Hello, How difficult would it be to (re)integrate the sigma2elastalert backend? Unfortunately my knowledge on the new pySigma is limited but i would imagine that the changes should be minimal to reimplement this as the es-qs backend still exists? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Check the YAML pipelines project from @frack113, he implemented Elastalert support based on the Elastic backend with processing pipelines. |
Beta Was this translation helpful? Give feedback.
Check the YAML pipelines project from @frack113, he implemented Elastalert support based on the Elastic backend with processing pipelines.