confluentinc / confluentinc/confluent-sigma
Question: how to handle different data formats?
- Dominant language
- JavaScript
- Stars
- 69
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Description
Came across this project, I like it a lot architecturally from an architectural standpoint. The combination of Sigma and eventing is fantastic, this enables separation from the underlying SIEM. I want to give this a go, but unless I'm mistaken I'm missing something from the documentation. We are standardizing on the ECS scheme (and there are more).
How is this handled in this library, can I just throw ECS at it and will it magically work? How about other data formats?
Thanks!
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names the documentation, Sigma, ECS, and other data formats but no files or tests. Start by locating the documentation that explains input handling and determine how format differences are treated. Done means clearly documenting whether ECS and other formats are supported and how users should provide them.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100