Files
blue-team-tools/tools/sigma/backends
ipninichuck 75ec169d5c added metadata field to the watcher alert
While utilizing Kibana to track watches directly from the watch index it became quickly apparent that useful metadata was not available. In my project's case it was the title, description and tags from the sigma rule. By adding them to the metadata field it makes it easier to utilize them in visualizations of the watches themselves. In the future perhaps the contents of the metadata field could be given as an option for each user.
2019-05-22 04:30:47 -07:00
..
2019-02-02 00:18:58 +01:00
2018-08-02 22:41:32 +02:00
2019-02-05 17:36:46 +01:00