Closed ericzinnikas closed 1 year ago
Wondering if you have any thoughts/plans on how to support custom Splunk commands (i.e. dedup)? It seems like these could be handled as custom type modifiers (like re), which would require adding to modifier_mapping.
dedup
re
No, this would be completely opposite to the idea of Sigma to be an universal language for expression of detections.
Wondering if you have any thoughts/plans on how to support custom Splunk commands (i.e.
dedup
)? It seems like these could be handled as custom type modifiers (likere
), which would require adding to modifier_mapping.