sigma-specification

Sigma Modifiers

The following document defines the standardized modifiers that can be used in Sigma.

Summary

Generic Modifiers

The following modifiers are considered generic modifiers and can be applied on all types of fields.

String Modifiers

The modifiers listed in this section can only be applied to string values.

Regular Expression

Encoding

Numeric Modifiers

The modifiers listed in this section can only be applied to numeric values.

Time Modifiers

The modifiers listed in this section can only be applied to date values. it extracts a numeric value from a date.

Warning: It is not designed to handle timezone or format conversions.

IP (Internet Protocol) Modifiers

The modifiers listed in this section can only be applied to IP values.

Specific Modifiers

History