diff --git a/tools/sigma/backends/elasticsearch.py b/tools/sigma/backends/elasticsearch.py index 5a51b4f6..76620993 100644 --- a/tools/sigma/backends/elasticsearch.py +++ b/tools/sigma/backends/elasticsearch.py @@ -1123,7 +1123,7 @@ class XPackWatcherBackend(ElasticsearchQuerystringBackend, MultiRuleOutputMixin) iaction = { "elastic":{ "transform":{ #adding title, description, tags on the event - "script": "ctx.payload.transform = [];for (int j=0;j