connectors icon indicating copy to clipboard operation
connectors copied to clipboard

[Elastic] Upgrade Sightings for Elastic connector

Open kmz161 opened this issue 1 year ago • 0 comments

Hello! Current Elastic connector create a background thread to poll for matches in the .siem-signals-* indices and will record them in OpenCTI as Sightings. But index .siem-signals-* is default alert index for Elasticsearch before 8.0.0. For new installations default alert index is .internal.alerts-security.alerts* https://www.elastic.co/guide/en/security/8.12/query-alert-indices.html#_alert_indices

Now there is no ability to receive Elastic SIEM Sightings for newest installations. I think it is need to upgrade API Request for different Elastic version.

kmz161 avatar Feb 02 '24 14:02 kmz161