Adaz
Adaz copied to clipboard
Build integration with Sigma rules
Suggestion:
- Clone Sigma rules repository or allow to specify custom ones
- Convert them to Elastalert format using
sigmac - Run Elastalert on the Elasticsearch/Kibana VM
- Output alerts to Elasticsearch