Increased test coverage for mapping corner cases

This commit is contained in:
Thomas Patzke
2018-10-16 14:53:12 +02:00
parent 265ce115a0
commit 44ff9d154e
4 changed files with 23 additions and 0 deletions
+1
View File
@@ -52,6 +52,7 @@ test-sigmac:
coverage run -a --include=$(COVSCOPE) tools/sigmac -rvdI -t fieldlist rules/ > /dev/null
coverage run -a --include=$(COVSCOPE) tools/sigmac -t xpack-watcher -O output=plain -O es=es -O foobar rules/windows/builtin/win_susp_failed_logons_single_source.yml > /dev/null
coverage run -a --include=$(COVSCOPE) tools/sigmac -t es-qs -o $(TMPOUT) tests/collection_repeat.yml > /dev/null
coverage run -a --include=$(COVSCOPE) tools/sigmac -t kibana -c tests/config-multiple_mapping.yml -c tests/config-multiple_mapping-2.yml tests/mapping-conditional-multi.yml > /dev/null
! coverage run -a --include=$(COVSCOPE) tools/sigmac -t xpack-watcher -O output=foobar -O es=es -O foobar rules/windows/builtin/win_susp_failed_logons_single_source.yml > /dev/null
! coverage run -a --include=$(COVSCOPE) tools/sigmac -t es-qs tests/not_existing.yml > /dev/null
! coverage run -a --include=$(COVSCOPE) tools/sigmac -t es-qs tests/invalid_yaml.yml > /dev/null
+4
View File
@@ -0,0 +1,4 @@
fieldmappings:
event_id:
- event_id
- eventid
+4
View File
@@ -0,0 +1,4 @@
fieldmappings:
EventID:
- event_id
- EventID
+14
View File
@@ -0,0 +1,14 @@
title: Contional mapping with multiple targets
status: test
description: Logpoint configuration causes conditional mapping with multiple results
author: Thomas Patzke
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
SubjectAccountName: Test
condition: selection
fields:
- EventID