This is the QRadar backend submodule for pySigma QRadar AQL.
- QRadarBackend: It provides a base backend for pySigma QRadar AQL.
-
QRadar_fields_pipeline: Supports only the mapped
Sigma fields
in the field mapping. -
QRadar_payload_pipeline: Uses
payload
search instead of unmapped fields.For payload search, the following value types are not supported:
- Boolean
- Null
- CIDR
- Regular Expression
- Numeric Comparison
pySigma_QRadar_base is licensed under the MIT License.