-
This is my JSON log from sandbox detonation:
and here is the converted JSONL version (using https://www.convertjson.com/json-to-jsonlines.htm): test_jsonl.json
And this is my Sigma rule (test_rule.json) which should trigger the event, but it failed:
This is the test command I used: Did I miss anything? Thanks! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Hello, I think this is because your rule is just a yaml to json conversion. It seems it has not been converted to Zircolite (more precisly SQLite) format. The related docs are here : https://github.com/wagga40/Zircolite/blob/master/docs/Usage.md#sysmon-rulesets-when-investigated-endpoints-have-sysmon-logs |
Beta Was this translation helpful? Give feedback.
Hello,
I think this is because your rule is just a yaml to json conversion. It seems it has not been converted to Zircolite (more precisly SQLite) format. The related docs are here : https://github.com/wagga40/Zircolite/blob/master/docs/Usage.md#sysmon-rulesets-when-investigated-endpoints-have-sysmon-logs