Skip to content

IBM/pySigma_QRadar_base

Repository files navigation

PySigma QRadar

This is the QRadar backend submodule for pySigma QRadar AQL.

Backend

  • QRadarBackend: It provides a base backend for pySigma QRadar AQL.

Pipelines

  • QRadar_fields_pipeline: Supports only the mapped Sigma fields in the field mapping.

  • QRadar_payload_pipeline: Uses payload search instead of unmapped fields.

    For payload search, the following value types are not supported:

    • Boolean
    • Null
    • CIDR
    • Regular Expression
    • Numeric Comparison

License

pySigma_QRadar_base is licensed under the MIT License.

Maintainers

About

QRadar backend and pipelines as submodule for pySigma-backend-QRadar-AQL and pySigma-backend-QRadar-KQL

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages