Closed leexuan closed 1 week ago
Sorry but sigmac is far out of support. Please retry your use case using pysigma + this backend and have a look for the different already available pipelines or if you need to adjust the resulted query to your customized field names you may have a look to post processing pipelines.
When convert a sigma rule to dsl with the following command, the generated dsl contains subfields, like "ParentImage.keyword". Is there anyone know how to remove the ".keyword" part from "ParentImage.keyword"?
The result show as follows: