connectors
connectors copied to clipboard
[Elastic] Upgrade Sightings for Elastic connector
Hello!
Current Elastic connector create a background thread to poll for matches in the .siem-signals-*
indices and will record them in OpenCTI as Sightings.
But index .siem-signals-*
is default alert index for Elasticsearch before 8.0.0.
For new installations default alert index is .internal.alerts-security.alerts*
https://www.elastic.co/guide/en/security/8.12/query-alert-indices.html#_alert_indices
Now there is no ability to receive Elastic SIEM Sightings for newest installations. I think it is need to upgrade API Request for different Elastic version.