Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EQL and Security options #589

Open
mvasuraja opened this issue May 11, 2023 · 0 comments
Open

EQL and Security options #589

mvasuraja opened this issue May 11, 2023 · 0 comments

Comments

@mvasuraja
Copy link

Hello,
I have a machine running Ubuntu 22.04. I have installed HELK with option 4. Everything is working fine.

I want to explore writing queries using EQL. I want to write queries to check if a sequence of events occurred.
I suppose this is available on a normal ELK stack under the Security-> Detect-> Alert/ Rules.

How do I do it with a HELK installation? On the Kibana screen, I dont see the Security option under Management at all.

Or is there some other option available, using KSQL or other tools?

Thanks in anticipation
Raja

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant