SigmaHQ / pySigma-backend-elasticsearch

pySigma Elasticsearch backend
GNU Lesser General Public License v3.0
42 stars 26 forks source link

Kubernetes pipeline (audit logs) #42

Closed LAripping closed 9 months ago

LAripping commented 9 months ago

This PR adds a pipeline that allows authoring of Sigma rules for Kubernetes Audit logs.

Lucene queries generated by the pipeline have been tested successfully against a live ELK instance, when converted from the rules defined here

More details are provided in the commit message

andurin commented 9 months ago

Thanks for the PR - merged.