You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@fanavarr in which release notes/updates did you read this? This query language is even included in one of their newest features (correlation searches). And also the S1 engineers i talked with are not aware that that the query language will be deprecated. Only the old language will be deprecated with the 2.0 language which contains a rename of the fields as what i stated in my first post.
Hi @svinusje you are right, bad choice of words from my end, I meant that pq is being more used with the Datase/Scalyr acquisition, which brings more querying capabilities, but you are right, I do apologize if my comment cause you any inconvenience.
When i have a look at the fields the pySigma-backend-sentinelone is generating it seems to use the old syntax.
for example: TgtFileLocation has become tgt.file.path , TgtFileIsSigned has become tgt.file.isSigned, ...
Can you have a look at the new naming please?
The text was updated successfully, but these errors were encountered: