Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 6 additions & 3 deletions sigma/backends/splunk/splunk.py
Original file line number Diff line number Diff line change
Expand Up @@ -60,13 +60,16 @@ def clean_field(field):

@classmethod
def add_field(cls, field):
cls.field_counts[field] = (
cls.field_counts.get(field, 0) + 1
# Count by the cleaned name: fields like a.x and b.x both map to the
# variable prefix "x" and must get different suffixes.
cleaned_field = cls.clean_field(field)
cls.field_counts[cleaned_field] = (
cls.field_counts.get(cleaned_field, 0) + 1
) # increment the field count

@classmethod
def get_field_suffix(cls, field):
index_suffix = cls.field_counts.get(field, "")
index_suffix = cls.field_counts.get(cls.clean_field(field), "")
if index_suffix == 1:
index_suffix = ""
return index_suffix
Expand Down
44 changes: 44 additions & 0 deletions tests/test_backend_splunk.py
Original file line number Diff line number Diff line change
Expand Up @@ -363,6 +363,50 @@ def test_splunk_disjunction_with_deferred_regex_no_search_or():
assert 'NOT fieldBCondition="true"' in query


def test_splunk_or_regex_dotted_fields_same_suffix(splunk_backend: SplunkBackend):
"""Fields a.x and b.x both clean to "x"; they must not share the rex/eval
variables, otherwise the second eval overwrites the first."""
SplunkDeferredORRegularExpression.reset()
result = splunk_backend.convert(
SigmaCollection.from_yaml(
"""
title: Test
status: test
logsource:
category: test_category
product: test_product
detection:
sel_a:
a.x|re: 'A'
filter_b:
b.x|re: 'B'
condition: sel_a or not filter_b
"""
)
)
assert result == [
'\n| rex field=a.x "(?<xMatch>A)"'
'\n| eval xCondition=if(isnotnull(xMatch), "true", "false")'
'\n| rex field=b.x "(?<xMatch2>B)"'
'\n| eval xCondition2=if(isnotnull(xMatch2), "true", "false")'
'\n| search xCondition="true" OR NOT xCondition2="true"'
]


def test_splunk_or_regex_dotted_fields_condition_names():
SplunkDeferredORRegularExpression.reset()
SplunkDeferredORRegularExpression.add_field("a.x")
assert SplunkDeferredORRegularExpression.get_field_condition("a.x") == "xCondition"
SplunkDeferredORRegularExpression.add_field("b.x")
assert SplunkDeferredORRegularExpression.get_field_condition("b.x") == "xCondition2"
assert SplunkDeferredORRegularExpression.get_field_match("b.x") == "xMatch2"
assert SplunkDeferredORRegularExpression.get_all_condition_fields() == {
"xCondition",
"xCondition2",
}
SplunkDeferredORRegularExpression.reset()


def test_splunk_regex_group_name_is_capped_for_long_fields():
SplunkDeferredORRegularExpression.reset()
field = "msg_normalized_header_subject"
Expand Down
Loading