Skip to content

Issue Adding Sigma Rules from Local Repo #13910

Closed Answered by defensivedepth
jstore-embers asked this question in 2.4
Discussion options

You must be logged in to vote

Greetings @jstore-embers. Good news! I have found the issue and PR'ed a fix for our next release: Security-Onion-Solutions/securityonion-soc#687

I have also added additional tests to make sure something like this scenario will be caught earlier.

Until then, you can search for any of the Sigma rules that don't have author fields and add a placeholder author field and value. That will allow all the rules to import without crashing SOC. Because it is a private ruleset, I will not list the rules here, but there are only 4 of them and you can find them with this:

grep -iLr "author" --include="*.yml" .

Thanks again for taking the time to troubleshoot this with me.

Replies: 2 comments 32 replies

Comment options

You must be logged in to vote
24 replies
@jstore-embers
Comment options

@jstore-embers
Comment options

@defensivedepth
Comment options

@jstore-embers
Comment options

@defensivedepth
Comment options

Comment options

You must be logged in to vote
8 replies
@jstore-embers
Comment options

@defensivedepth
Comment options

@jstore-embers
Comment options

@defensivedepth
Comment options

@jstore-embers
Comment options

Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants