Skip to content

Sigma base fields that work for all vendors #2552

Closed Answered by frack113
esikuriansky asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

Rule should use the original field name.
The space in field nane are replace by _

For windows is easy : Event Viewer select Details and Xml.
For BIND need to works with the rfc 😄

In any case DO NOT use ECS , Splunk or SIEM custom field name.

Not all the backend mapping files are up to date, some old field name may still be in it but not by the rules anymore...
Hope to be usefull

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by nasbench
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants