SigmaHQ/sigma-specification

How to use Sigma correlations

alexpwns opened this issue · 7 comments

I was reading through the wiki and noticed this line, "Aggregations in the condition are deprecated and will be replaced with Sigma correlations.", but can't seem to find any additional information on how to use Sigma correlations. Is there any additional info on Sigma correlations?

Any update on what is going on with Correlations? The provisional spec is approaching two years old... will it ever be mainline?

Should this be closed? Correlations seems to not be marked provisional anymore

so, did they get rid of the idea behind correlations? I haven't seen a working example still. Tried creating my own, similar to the blog article but I just get an error when sigma can't find a detection section in the rule. Then if I add one, a condition is needed and when I do that, I just get three distinct rules and no actual correlation.