You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Splunk table is processed thanks to the fact that the author of the Sigma rule issued the fields for the analyst. I would like to have an option to avoid that and have my post-processing handle the | table part, is there any transformation rule for that purpose?
Sigma rule:
title: Load Undocumented Autoelevated COM Interface
id: fb3722e4-1a06-46b6-b772-253e2e7db933
...
fields:
- ComputerName
- User
- SourceImage
- TargetImage
- CallTrace
...
level: high
The text was updated successfully, but these errors were encountered:
I've created a new query post-processing transformation replace with the parameters pattern an replacement. The following (untested) should do what you want:
Hi!
I am currently using the
splunk_windows
pipeline and I am looking for a pipeline option to avoid the Splunk table output as the following:The Splunk table is processed thanks to the fact that the author of the Sigma rule issued the fields for the analyst. I would like to have an option to avoid that and have my post-processing handle the
| table
part, is there any transformation rule for that purpose?Sigma rule:
The text was updated successfully, but these errors were encountered: