Skip to content

Sigma rules not working #2052

Discussion options

You must be logged in to vote

Hey @feayeas as the error message expresses, the method used in a rule is not implemented in Timesketch (or more precise in Elastic).

Besides, it is not recommended (and not supported) to just copy the whole Sigma project into your rule folder. It will break things and some rules will create false results.
(e.g. #1532)

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jaegeral
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants