pySigma-backend-elasticsearch
pySigma-backend-elasticsearch copied to clipboard
Transform current output formats to postprocessing
The pySigma (>=0.10.0) post-processing feature allows a much more dynamic way to create different output formats.
ES Backend should be rewritten including the current output formats as templates.
Does this mean we can have many detection types (other types than query
), such as new_terms
or threshold
?
It depends what detection type means. If it embeds a Lucene or EQL query that is already generated by the backend then this is possible. If that are independent query languages then they have to be implemented as custom backend.