Ross Wolf
|
9d22970e21
|
Add EQL rules and schema validation (#297)
* Add EQL rules and schema validation
* Lint nitpick
* Rename get_schema_from_eql
* Add EQL default language
* Rename parsed_kql to parsed_query
* Fix parsed_kql method call in loader
* Autopopulate dependent values
|
2020-09-16 08:36:48 -06:00 |
|
Ross Wolf
|
db4f50d4b8
|
Improve the validation and testing time (#61)
* Improve the validation and testing time
* Lint fix
* Cache schema validation
|
2020-07-15 08:05:55 -06:00 |
|
Andrew Pease
|
e0f2e8b4a9
|
Add dataset and index to network rules (#15)
* Add dataset and index to network rules
* Restore iptables changes
* Fix beats parsing logic
* Updated date and ECS version
* Only update modules if empty
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Co-authored-by: Ross Wolf <31489089+rw-access@users.noreply.github.com>
|
2020-07-08 13:19:35 -06:00 |
|
Ross Wolf
|
3b305d3003
|
Add rule loader and dependencies
Co-Authored-By: Justin Ibarra <brokensound77@users.noreply.github.com>
|
2020-06-29 23:17:42 -06:00 |
|