From ddeb57aa2b73cc30fe971fa01dec0b6ef0cb5cd6 Mon Sep 17 00:00:00 2001 From: "dmytro.tarnopolskyi" Date: Wed, 6 Dec 2023 12:24:46 +0100 Subject: [PATCH] fix bug while generating description in spl-rule --- .../app/converter/platforms/splunk/renders/splunk_alert.py | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/siem-converter/app/converter/platforms/splunk/renders/splunk_alert.py b/siem-converter/app/converter/platforms/splunk/renders/splunk_alert.py index c6b233de..3ffeca70 100644 --- a/siem-converter/app/converter/platforms/splunk/renders/splunk_alert.py +++ b/siem-converter/app/converter/platforms/splunk/renders/splunk_alert.py @@ -55,13 +55,9 @@ def finalize_query(self, prefix: str, query: str, functions: str, meta_info: Met rule = rule.replace("", severity_map.get(meta_info.severity, "1")) rule_description = get_rule_description_str( description=meta_info.description or 'Autogenerated Splunk Alert.', - license=meta_info.license, - mitre_attack=meta_info.mitre_attack + license=meta_info.license ) rule = rule.replace("", rule_description) - - description = f"{meta_info.description or 'Autogenerated Splunk Alert.'} License: {meta_info.license}." - rule = rule.replace("", description) mitre_techniques = self.__create_mitre_threat(meta_info=meta_info) if mitre_techniques: mitre_str = f"action.correlationsearch.annotations = {mitre_techniques})" pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy