Arcuri Davide
Arcuri Davide

> optional: filter on columns https://elasticsearch-py.readthedocs.io/en/v8.13.0/api/esql.html#elasticsearch.client.EsqlClient.query
This could be easily done but then it could degenerate easily. If I have multiple csv, excel files, json or a local dbs? Following similar need you should support everything....
It's not so clear, Can you please provide a screen? Normally the result report contains also the name of the server instance to understand where the observable has been run.
Probably duplicated of https://github.com/TheHive-Project/Cortex-Analyzers/issues/804
Unfortunately - the README is not up to date but It should be ok to understand initial step to sync plugins and symbols. You can find all information for first...