-
Notifications
You must be signed in to change notification settings - Fork 96
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
detected_events.json issue #60
Comments
Hi, Your file must have 1 json event per line (JSONL) when using json as input. |
Yes, I did. But it doesn't work. Should I copy my Json here? |
Yeah please share if you can. |
I wanted to know, I have analyzed and get EVTX file using autopsy, So when i am running the following command python zircolite.py --evtx ../Autopsy-SAMPLES/ --ruleset rules/rules_windows_sysmon.json --template templates/exportFor it is giving me following output
-= Standalone SIGMA Detection tool for EVTX/Auditd/Sysmon Linux =- [+] Checking prerequisites It doesn't write anything in detected_events.json and also not creating data.js for gui representation, why is that? |
From what I see the simple explanation is that nothing has been detected. It means that no sigma rules have matched against your EVTX file. The ruleset you used is for Windows system with sysmon installed, if you don’t have sysmon use the generic ruleset. NB : for the gui, using the —package option is easier |
I am importing a JSON file from Splunk and trying to analyze it. My detected_events.json shows empty. Do i need the EVTX or is it because of the splunk?
The text was updated successfully, but these errors were encountered: