grafana/pySigma-backend-loki

Ensure W3C field names are mapped correctly in relevant pipelines

kelnage opened this issue · 0 comments

As described on this page, there are standardised field names that many Sigma rules use. We should ensure that all relevant pipelines are able to map these wherever possible - this could include creating a broader test suite to validate the mapping is being done correctly.

This was made apparent after SigmaHQ/sigma#3855 was committed.