SigmaHQ / pySigma-backend-splunk

pySigma Splunk backend
GNU Lesser General Public License v2.1
34 stars 18 forks source link

Support custom Splunk commands #16

Closed ericzinnikas closed 1 year ago

ericzinnikas commented 1 year ago

Wondering if you have any thoughts/plans on how to support custom Splunk commands (i.e. dedup)? It seems like these could be handled as custom type modifiers (like re), which would require adding to modifier_mapping.

thomaspatzke commented 1 year ago

No, this would be completely opposite to the idea of Sigma to be an universal language for expression of detections.