pySigma
pySigma copied to clipboard
[Filters] Sigma Filters don't work in specific mutliple rules definition scenario
I noticed Sigma Filters don't work when multiple rule references are put upon them. No idea why yet.
Error: Error while conversion: Detection '_filt_icbtcxllye' not defined in detections in /.../sigma/rules/okta/okta_brute_force_followed_by_login.yml
Sigma CLI version:
1.0.3 (online pypi.org: 1.0.2)
YAML:
title: Okta Failed Login
id: 91b76b84-8589-47aa-9605-c837583b82a9
name: okta_failed_login
status: experimental
logsource:
product: okta
service: okta
detection:
selection:
event_type: user.session.start
outcome.result: FAILURE
condition: selection
---
title: Okta Successful Login
id: 91b76b84-8589-47aa-9605-c837583b82a3
name: okta_successful_login
status: experimental
logsource:
product: okta
service: okta
detection:
selection:
event_type: user.session.start
outcome.result: SUCCESS
condition: selection
---
title: Just Some User
id: 91b76b84-8589-47aa-9605-c837583b8222
status: experimental
logsource:
product: okta
service: okta
filter:
rules:
- okta_successful_login
- okta_failed_login
selection:
actor.alternate_id: "some_user"
condition: selection