Replies: 1 comment
-
IF we go that way, why not use |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I spoke about this idea at BSides Athens with some great people.
The idea is that Sigma Filter Rules should have an expiry, where a Filter automatically stops excluding matches after a given date. This is in contrast to "disabling" a rule, and forgetting to switch it back on after a given date.
For this, 2w might apply to
date
ormodified
.The alternative for this is to get the timestamp in 2w and compare timestamp against the event's time, which is also another viable solution.
Beta Was this translation helpful? Give feedback.
All reactions