diff --git a/tools/sigma/backends/ala.py b/tools/sigma/backends/ala.py index f70a9dbf1..c053004ee 100644 --- a/tools/sigma/backends/ala.py +++ b/tools/sigma/backends/ala.py @@ -124,7 +124,7 @@ class AzureLogAnalyticsBackend(SingleTextQueryBackend): elif val.endswith("*"): op = "startswith" val = re.sub('([".^$]|(?![*?]))', '\g<1>', val) - val = re.sub('(\\\\\*|\*)', '.*', val) + val = re.sub('(\\\\\*|\*)', '', val) val = re.sub('\\?', '.', val) if "\\" in val: return "%s @'%s'" % (op, self.cleanValue(val))