Skip to content

chore: Skip Splunk datamodel conversion for rules using regex modifier#47

Merged
0xFustang merged 1 commit intomainfrom
chore/exclude-datamodel-regex-splunk
Feb 17, 2026
Merged

chore: Skip Splunk datamodel conversion for rules using regex modifier#47
0xFustang merged 1 commit intomainfrom
chore/exclude-datamodel-regex-splunk

Conversation

@0xFustang
Copy link
Collaborator

Description

Rules using the |re (regex) Sigma modifier are now marked as not compatible when the output format is data_model on the Splunk backend, as this combination is currently broken (SigmaHQ/pySigma-backend-splunk#60). A warning is logged and the rule is skipped instead of producing an invalid query.

@0xFustang 0xFustang self-assigned this Feb 17, 2026
@0xFustang 0xFustang merged commit 1f0d192 into main Feb 17, 2026
2 checks passed
@0xFustang 0xFustang deleted the chore/exclude-datamodel-regex-splunk branch February 17, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant