mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
2f5eb08b41
When no field is present, use "count" , when field is present use "dc(field)". As described in the Sigma specifications. Splunk throws errors when using "count()" with empy fields. use "count" instead. |
||
---|---|---|
.. | ||
backends | ||
config | ||
parser | ||
__init__.py | ||
configuration.py | ||
filter.py |