Sigma2SplunkAlert icon indicating copy to clipboard operation
Sigma2SplunkAlert copied to clipboard

1st Version of collection transforming

Open a2tf opened this issue 5 years ago • 1 comments

Hey Patrick

Sigma uses collections, and the output of the sigma converter places each of the searches in that collection on a new line. This breaks the search syntax in the savedsearches.conf file. I added the "or_collections" transforming command, which just adds these different searches of a collection with an " OR " to a one liner.

e.g.: rules/windows/sysmon/sysmon_cmstp_execution.yml rules/windows/sysmon/sysmon_logon_scripts_userinitmprlogonscript.yml and so on...

Hope that unsolves syntax errors as well for others...

Andi

a2tf avatar Nov 27 '19 13:11 a2tf

Hi, sorry for the late response. I will review it as soon as possible. Thank you for your contribution.

P4T12ICK avatar Dec 23 '19 09:12 P4T12ICK