SigmaHQ / pySigma-backend-splunk

pySigma Splunk backend
GNU Lesser General Public License v2.1
33 stars 17 forks source link

Include alert descriptions in savedsearch output #9

Closed ericzinnikas closed 2 years ago

ericzinnikas commented 2 years ago

If the sigma rule contains a description, include it in the generated savedsearch.conf output, so it is visible in the UI when running searches and viewing search results.

If there is no description available, leave as an empty string (per the spec).

thomaspatzke commented 2 years ago

Thanks for the PR!