-
Notifications
You must be signed in to change notification settings - Fork 7
Description
@fukusuket
In default_profile.txt
, I updated the config file as follows:
Timestamp: '.eventTime'
RuleTitle: 'sigma.title'
RuleAuthor: 'sigma.author'
Level: 'sigma.level'
EventName: '.eventName'
EventSource: '.eventSource'
AWS-Region: '.awsRegion'
SrcIP: '.sourceIPAddress'
UserAgent: '.userAgent'
UserName: '.userIdentity.userName'
UserType: '.userIdentity.type'
UserAccountID: '.userIdentity.accountId'
UserARN: '.userIdentity.arn'
UserPrincipalID: '.userIdentity.principalId'
UserAccessKeyID: '.userIdentity.accessKeyId'
EventID: '.eventID'
RuleID: 'sigma.id'
But in the RuleAuthor output is -
. Could you take a look at this?
(Btw, RuleID
is working.)
fukusuket
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working