Skip to content

Are there any complete examples of using 'change_logsource' in a pipeline rule? #192

Closed Answered by joshnck
BCall-BT asked this question in Q&A
Discussion options

You must be logged in to vote
transformations:
- id: change_logsource
  type: change_logsource
  category: security
  rule_conditions:
  - type: logsource
    category: process_creation

That should do it for you!

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by thomaspatzke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants