4f19ef5708
Technically, Graylog is ES. Fixes and improvements for ES didn't propagate to Graylog, now they do.
This package contains libraries for processing of Sigma rules and the following command line tools:
- sigmac: converter between Sigma rules and SIEM queries:
- Elasticsearch query strings
- Kibana JSON with searches
- Splunk SPL queries
- Elasticsearch X-Pack Watcher
- Logpoint queries
- merge_sigma: Merge Sigma collections into simple Sigma rules.
- sigma2misp: Import Sigma rules to MISP events.