We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When using the sigma rule
title: Test Rule for System Process status: test logsource: category: process_creation detection: sel: ProcessId: 4 condition: sel
the resulting query is dataset=xdr_data | filter (event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START) and (action_process_os_pid = "4")
dataset=xdr_data | filter (event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START) and (action_process_os_pid = "4")
This then throws the error Value 4 for operator = is invalid. expected number but received string
Value 4 for operator = is invalid. expected number but received string
The text was updated successfully, but these errors were encountered:
7RedViolin
Successfully merging a pull request may close this issue.
When using the sigma rule
the resulting query is
dataset=xdr_data | filter (event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START) and (action_process_os_pid = "4")
This then throws the error
Value 4 for operator = is invalid. expected number but received string
The text was updated successfully, but these errors were encountered: