Skip to content

What's type of regex? #3658

Closed Answered by frack113
kazuminn asked this question in Q&A
Oct 30, 2022 · 1 comments · 3 replies
Discussion options

You must be logged in to vote

From https://github.com/SigmaHQ/sigma-specification/blob/main/Sigma_1_0_1.md#modifier-types
re: value is handled as regular expression by backends. Currently, this is only supported by the Elasticsearch query string backend (es-qs). Further (like Splunk) are planned or have to be implemented by contributors with access to the target systems

As the backend are in python for sigmac and Pysigma , python ?
Try a regex from a rule in https://regex101.com/r/MgB2Nt/1 , only .Net C# did not works.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@nasbench
Comment options

@kazuminn
Comment options

@nasbench
Comment options

Answer selected by kazuminn
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants