Skip to main content

parse_sigma_yaml

Function parse_sigma_yaml 

Source
pub fn parse_sigma_yaml(yaml: &str) -> Result<SigmaCollection>
Expand description

Parse a YAML string containing one or more Sigma documents.

Handles multi-document YAML (separated by ---) and collection actions (action: global, action: reset, action: repeat).

Reference: pySigma collection.py SigmaCollection.from_yaml