diff --git a/tools/sigmac/logsource_mapping.py b/tools/sigmac/logsource_mapping.py index b75386d82..61bb6e51d 100644 --- a/tools/sigmac/logsource_mapping.py +++ b/tools/sigmac/logsource_mapping.py @@ -141,7 +141,7 @@ def need_field_conversion(self) -> bool: return False def is_detectable_fields(self, keys) -> bool: - common_fields = ["CommandLine", "ProcessId", "OriginalFileName"] + common_fields = ["CommandLine", "ProcessId"] keys = [re.sub(r"\|.*", "", k) for k in keys] keys = [k for k in keys if k not in common_fields] if not keys: