Velocidex / velociraptor-sigma-rules

A Compiler from Sigma rules to VQL
10 stars 4 forks source link

Add Field Mappings to Log Sources #18

Closed bmcder02 closed 8 months ago

bmcder02 commented 10 months ago

Addressing #14 , currently invalid fields can be added to rules, with a rule requiring a field that doesn't exist. This PR will add fields to each log source, so we can find invalid fields during linting.