Expand description
Semantic checks on parsed detections.
The parser runs these checks on every detection it builds, so rule parse,
lint, the LSP, evaluation, and conversion reject the same invalid rules, as
pySigma does when it loads a rule. IR lowering repeats the item checks for
detections that are built or rewritten after parsing.
Functionsยง
- check_
cidr - Check that a
|cidrvalue isaddress/prefixwith no host bits set, as pySigma requires. - check_
detection_ item - Check one detection item: its modifier chain, and every value against the type its modifiers require.
- check_
modifiers - Check that a modifier chain sets at most one operator and combines only modifiers that compose.
- check_
regex - Check that a
|revalue is a valid regular expression. - exists_
flag - The boolean an
|existsvalue stands for.