-
Notifications
You must be signed in to change notification settings - Fork 200
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New feature: add support for |all
#1038
Comments
@YamatoSecurity |
@YamatoSecurity @itiB @hitenkoku @fukusuket 日本語で失礼します。
|
が良いかと思いました! 理由: |
@fukusuket 個人的にはパイプからスタートするものを取り扱うとするとgrep機能には正直違和感があるなぁと思っています。 以下のURLで確かにそのようにするとかいてはいるけどdocument内では確認できませんでした…… 関連するところはこことかですかね? |
そうですよね、
確かに、こちら少し影響ありそうですね!実装の際は、気にしていただけると幸いです🙇 |
@kazuminn Are you interested in implementing this?
There are several rules that use
|all
to specify that all keywords need to exist.Example:
In this rule example, all of the keywords in
keywords_cmdlet
need to exist somewhere (any field) in the event log. Also, at least one keyword inkeywords_params
needs to exist in a field.|all
rules:The text was updated successfully, but these errors were encountered: