wazuh-ruleset
wazuh-ruleset copied to clipboard
Accept wider range of IOS timestamp formats
(Note: it would be simpler to use .*\d*\s*\w*
to capture optional
milliseconds and timezone, but that pattern doesn't appear to work)
Fixes problem identified in https://github.com/wazuh/wazuh/issues/2399 and adds some test cases
Rebased to current master
Hello @candlerb
First, sorry for the late answer. Thank you for your contribution to the Ruleset project. I'm going to review your PR and give you an answer shortly.
Kind regards, Eva