Closed webhead404 closed 4 months ago
Fixes #41. The pipeline accounts for EQL as a query language but doesn't import into the SIEM correctly. Changed language from lucene to eql and type of rule from query to eql.
lucene
eql
query
Thanks! Please also adapt the now failing test.
Updated the test file and ran the tests successfully!
Great, thanks!
Fixes #41. The pipeline accounts for EQL as a query language but doesn't import into the SIEM correctly. Changed language from
lucene
toeql
and type of rule fromquery
toeql
.