pySigma icon indicating copy to clipboard operation
pySigma copied to clipboard

[Filters] Sigma Filters don't work in specific mutliple rules definition scenario

Open sifex opened this issue 1 year ago • 0 comments

I noticed Sigma Filters don't work when multiple rule references are put upon them. No idea why yet.

Error: Error while conversion: Detection '_filt_icbtcxllye' not defined in detections in /.../sigma/rules/okta/okta_brute_force_followed_by_login.yml

Sigma CLI version: 1.0.3 (online pypi.org: 1.0.2)

YAML:

title: Okta Failed Login
id: 91b76b84-8589-47aa-9605-c837583b82a9
name: okta_failed_login
status: experimental
logsource:
    product: okta
    service: okta
detection:
    selection:
        event_type: user.session.start
        outcome.result: FAILURE
    condition: selection
---
title: Okta Successful Login
id: 91b76b84-8589-47aa-9605-c837583b82a3
name: okta_successful_login
status: experimental
logsource:
    product: okta
    service: okta
detection:
    selection:
        event_type: user.session.start
        outcome.result: SUCCESS
    condition: selection
---
title: Just Some User
id: 91b76b84-8589-47aa-9605-c837583b8222
status: experimental
logsource:
    product: okta
    service: okta
filter:
    rules:
        - okta_successful_login
        - okta_failed_login
    selection:
        actor.alternate_id: "some_user"
    condition: selection

sifex avatar Jun 24 '24 14:06 sifex