d81946df39
- Added log source rewriting - Removed log source merging condition type setting - Simplified SigmaLogsourceConfiguration constructor - Condition is generated in SigmaParser instead of SigmaLogsourceConfiguration Missing: - Merging of raw config dict for backends that rely on this (es-dsl)
10 lines
211 B
YAML
10 lines
211 B
YAML
logsources:
|
|
process_creation:
|
|
category: process_creation
|
|
product: windows
|
|
conditions:
|
|
EventID: 1
|
|
rewrite:
|
|
product: windows
|
|
service: sysmon
|