Pre-Release Qradar Backend #53
Closed
nNipsx-Sec
started this conversation in
Ideas
Replies: 2 comments 1 reply
-
Hi! At a first glance this already looks very good! Will look more deeply into later and start to integrate it into Sigma CLI. I'm sure this will be very useful for Sigma QRadar users! |
Beta Was this translation helpful? Give feedback.
1 reply
-
Already integrated in sigma cli - See https://github.com/SigmaHQ/pySigma-plugin-directory/blob/main/pySigma-plugins-v1.json#L88-L96 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi @thomaspatzke,
I have pre-release Qradar Backend with new module for generate extensions for easier deploy rules in this SIEM. Can you check it in this link https://github.com/nNipsx-Sec/pySigma-backend-qradar
With pipeline of Qradar, now i can't list and mapping all field so i'll try update full field in near future
With new feature for Qradar is Extensions:
This backend i build base on Splunk Backend and maybe it's have some issue please tell me so i'll fix soon ASP
Thanks,
Hope so it's helpful for Community.
Beta Was this translation helpful? Give feedback.
All reactions