-
I'm trying to use pipelines with sigma-cli or https://sigconverter.io/ to replace the default index patterns used when converting to an elastic siem rule. Any attempt I make either errors out or does nothing. Below is the only reference I can find, but it does not work |
Beta Was this translation helpful? Give feedback.
Answered by
joshnck
Mar 24, 2024
Replies: 1 comment
-
transformations:
- id: change_logsource
type: change_logsource
category: security
rule_conditions:
- type: logsource
category: process_creation That should do it for you! |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
thomaspatzke
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
That should do it for you!