Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fields not up to date? #11

Open
svinusje opened this issue Jun 14, 2024 · 3 comments
Open

Fields not up to date? #11

svinusje opened this issue Jun 14, 2024 · 3 comments

Comments

@svinusje
Copy link

When i have a look at the fields the pySigma-backend-sentinelone is generating it seems to use the old syntax.

for example: TgtFileLocation has become tgt.file.path , TgtFileIsSigned has become tgt.file.isSigned, ...

Can you have a look at the new naming please?

@ghost
Copy link

ghost commented Jul 2, 2024

Hi @svinusje , SentinelOne Query Language is being deprecated by S1 itself, as per updates and products release notes they seem to be moving to Power Query, so you should take a look at https://github.com/7RedViolin/pySigma-backend-sentinelone-pq

@svinusje
Copy link
Author

@fanavarr in which release notes/updates did you read this? This query language is even included in one of their newest features (correlation searches). And also the S1 engineers i talked with are not aware that that the query language will be deprecated. Only the old language will be deprecated with the 2.0 language which contains a rename of the fields as what i stated in my first post.

@ghost
Copy link

ghost commented Jul 10, 2024

Hi @svinusje you are right, bad choice of words from my end, I meant that pq is being more used with the Datase/Scalyr acquisition, which brings more querying capabilities, but you are right, I do apologize if my comment cause you any inconvenience.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant