dsiem
dsiem copied to clipboard
Taxonomy
Where should we add taxonomy information to write taxonomy rule?
Hi,
Taxonomy Rule is written the same way as a Plugin Rule, the only difference is its identifier.
To make a Taxonomy Rule, you can specify your rule type
as TaxonomyRule
and use product
, category
, and optionally subcategory
fields as identifier instead of plugin_id
and plugin_sid
. You can read more about it in this documentation.
Thank you for the information. Where should I create the Product, Category and Subcategory information? Should we write the file containing this information under the internal/pkg/ossincnv folder?
You just write it as part of the directive. Here's an example of taxonomy rule: https://github.com/defenxor/dsiem/blob/a51a6c0b601af1c99714ccc2502d892371fa3ab3/internal/pkg/dsiem/siem/fixtures/directive1/directives_dsiem-backend-0_testing1.json#L108-L123