-
Notifications
You must be signed in to change notification settings - Fork 203
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sigma correlation rule count does not show up in 'Events with hits' #1373
Comments
@YamatoSecurity If either issue does not work as intended, I will fix it both!💪 |
@YamatoSecurity
|
Thanks! Yes, I think we should include the |
What do you mean by I was thinking the total number of events that any rule matched on. What do you think? |
@YamatoSecurity |
@fukusuket Sorry I noticed this bug after merging the previous PR..
I am using this rule:
and this command:
./target/release/hayabusa csv-timeline -d ../hayabusa-sample-evtx -w -r ~/Desktop/test.yml
It gives me this summary:
Problems:
Top 5 computers with most unique detections
shows onlyn/a
but should include the correlation rule resultsEvents with hits / Total events: 0 / 26,341 (Data reduction: 26,341 events (100.00%))
should sayEvents with hits / Total events: 2 / 26,341 (Data reduction: 26,339 events (99.99%))
The text was updated successfully, but these errors were encountered: