sigma
sigma copied to clipboard
fix capitalization of user directory
Tested this rule with Win10 logs and only worked with capital users directory
This is a backend problem. I guess that you've indexed your data case-sensitive in an ElasticSearch, am I right?
SIgma is case insensitive for the data , It is a a elastic keyword vs text field trouble