-
Notifications
You must be signed in to change notification settings - Fork 234
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add IN operator for sumologic connector #845
Conversation
Codecov Report
@@ Coverage Diff @@
## develop #845 +/- ##
===========================================
+ Coverage 63.81% 63.84% +0.02%
===========================================
Files 452 452
Lines 39949 39964 +15
===========================================
+ Hits 25495 25514 +19
+ Misses 14454 14450 -4
Continue to review full report at Codecov.
|
stix_pattern = "[user-account:display_name IN ('abc', 'def')]" | ||
query = translation.translate('sumologic', 'query', '{}', stix_pattern) | ||
_, from_time, to_time = query_constructor.convert_timestamp(query) | ||
queries = "{\"query\": \"displayName = (abc OR def)\", \"fromTime\": \"%s\", \"toTime\": \"%s\"}" \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
are you sure this is a valid translated query? have you checked the API if it has any IN operator or similar kind of operator support? if there's no IN operator support exists then it should work like OR operator.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi Azam,
I refer to the sumologic query doc here https://help.sumologic.com/05Search/Get-Started-with-Search/How-to-Build-a-Search/Keyword-Search-Expressions#examples
IN operator is NOT supported naturally from sumologic query, we will need to translate it to an combination of "=" and "OR", there are some examples in the docs using "=" and "OR"
9418592
to
9ba0731
Compare
stix_shifter_modules/sumologic/tests/stix_translation/test_sumologic_stix_to_query.py
Outdated
Show resolved
Hide resolved
stix_shifter_modules/sumologic/stix_translation/query_constructor.py
Outdated
Show resolved
Hide resolved
* CrowdStrike: Adding IN operator support (#842) * Add IN operator for sumologic connector (#845) * Added IN operator for Vision One UDI connector (#861) * Adding IN operator support to CB connector (#835) * fix cb operator lookup Co-authored-by: Md Azam <mdazam@ca.ibm.com> Co-authored-by: Jingqiu Du <jingqiu@ca.ibm.com> Co-authored-by: Arthur Muradyan <arthur.muradyan@ibm.com>
No description provided.