sigma
sigma copied to clipboard
The 'near' aggregation operator is not yet implemented for this backend
How to avoid the error of bypass while converting sigma to elastalert?
./sigmac -t elastalert -r /home/det/sigma/rules/windows/process_creation -o /home/det/sigma/converted_windows/ -e yml -c elk-winlogbeat
An unsupported feature is required for this Sigma rule (/home/det/sigma/rules/windows/process_creation/proc_creation_win_apt_turla_commands_medium.yml): None : The 'near' aggregation operator is not yet implemented for this backend
You can use --ignore-backend-errors or -I option