Skip to content

Linux Authentication Failure - Playbook Help #4562

Closed Answered by nasbench
Mav1814 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @Mav1814

This seems to be an issue in your mapping and conversion. You might be storing the linux logs in a different index and you don't have the correct mapping to map the logsource :) So best take a look at that. And make sure that you're manual query looks like the converted query.

Also as a side note the Sigma discussion here in this repo are related to discussion around Sigma rules and related ideas. If you have issues with conversion and you're using an open source backend, you can take it up there.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by nasbench
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants