Closed frack113 closed 2 years ago
Thank you very much @frack113 ! :)
Hello @neu5ron ! Would you mind sharing your thoughts on this? I believe it was done this way for a reason? Is this part of the pipeline that you have not merged yet? Whenever you have some time 🙏🏾 thank you !
Hi,
for sigma rule, I have check rdp.yml that have the field name in name
with "." .
Thank you @frack113 !
looks ok, sometimes zeek is output to nest as _ or .'s doesn't really matter. LGTM
When check sigma rule find a diff ("_" rather than "."). Fix name according to the reference https://docs.zeek.org/en/v4.1.1/logs/x509.html Some field name are not in the reference.