Closed HenrikWittemeier closed 2 days ago
Hi! My first thought was that IncludeFieldCondition
would do it, but as field name condition it's not applied to a rule transformation as the logsource change is. Shouldn't be a big thing to implement.
Just pushed the implementation, will be contained in the next release.
In my processing pipeline id like to change the logsource of a rule based on the fields it has. My network events on different layers have different logsources but all have ["linux","network_event"] as predefined logsource. So i need to change the logsource depending on "IP" or "Hostname" fields in the rule. In my understanding there is no such possibility at the moment. I found the RuleContainsDetectionItemCondition but it only works when i set field and value. I would appreciate a RuleProcessingCondition that has only the Fieldname as Input or a workaround to achieve this.