SigmaHQ / pySigma-backend-splunk

pySigma Splunk backend
GNU Lesser General Public License v2.1
33 stars 17 forks source link

Adding custom cim mapping kv #33

Closed IgorHrkswxryski closed 7 months ago

IgorHrkswxryski commented 7 months ago

Hi there !

Is there any possibilities to add custom k/v for cim mapping (ex : ProcessName for splunk_sysmon_process_creation_cim_mapping) without touching your code ? Perhaps through Processing Pipelines ? Or do you prefer a pull requests with new data_model mapping ?

Thanks in advance,

See you !

thomaspatzke commented 7 months ago

Yes, you can define your custom processing pipeline in YAML format and use them. Non-standard mappings are not intended to be added to the packaged processing pipelines as they are specific to an environment.