Hub rules-elk

rules-elk

v5 public Verified

ELK Stack

The ELK Stack (Elasticsearch, Logstash, Kibana) is a toolset for log searching and visualization. These rules govern log aggregation, index management, and dashboard creation for observability and security analytics.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-elk →
Severity
6 error 1 warn 0 info
demo.cast
The ELK Stack (Elasticsearch, Logstash, Kibana) is a toolset for log searching and visualization. These rules govern log aggregation, index management, and dashboard creation for observability and security analytics.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

elk

elk-deprecated-transport-client warning log

The Elasticsearch TransportClient (port 9300 binary protocol) was removed in Elasticsearch 8.x. Migrate to the Java High Level REST Client or the new Java API Client (co.elastic.clients:elasticsearch-java) to maintain support and receive security patches.

Rule source requires an active Pro or Enterprise subscription.
elk-hardcoded-credentials error block

Hardcoded credential detected in ELK config — CWE-798. Hard-coding Elasticsearch/Kibana passwords in config files means every developer with repo access has cluster credentials. Use environment variable substitution (e.g., '${ES_PASSWORD}') or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
elk-inline-script-enabled error block

Elasticsearch dynamic inline script execution is enabled — CWE-94. This allows any authenticated user to run arbitrary Groovy/Painless code on the cluster nodes, leading to RCE. Remove 'script.inline: true' or restrict to 'script.inline: sandboxed' with a strict operator allow-list.

Rule source requires an active Pro or Enterprise subscription.
elk-network-host-any error block

Elasticsearch is configured to bind to all network interfaces — CWE-284. Combined with disabled security this directly exposed the Meow botnet attack (2020) that deleted 13,000+ indices. Bind to a specific internal interface ('network.host: 127.0.0.1' or a private IP) and enforce TLS + auth before opening to any network.

Rule source requires an active Pro or Enterprise subscription.
elk-stored-script-enabled error block

Elasticsearch stored script execution is enabled — CWE-94. Stored scripts persist on the cluster and can be triggered by any user with write access. Use only pre-approved scripts, restrict with 'script.allowed_types: none' in production.

Rule source requires an active Pro or Enterprise subscription.
elk-tls-disabled error block

Elasticsearch TLS is explicitly disabled — CWE-319. Transport credentials and index data travel in plaintext. Enable TLS for both HTTP and transport layers and provide a signed certificate/keystore.

Rule source requires an active Pro or Enterprise subscription.
elk-xpack-security-disabled error block

Elasticsearch X-Pack security is explicitly disabled — CWE-306. Without security enabled, any network-accessible node accepts unauthenticated reads and writes, including full index deletion and cluster shutdown. Remove this line or set it to 'true'.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
98bc27acf9945da7d52e430d05029f393bb6c2149e80aba0a6425ce996036f1b
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-elk/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-elk. The published version only bumps when a maintainer resyncs.

No commit history available.