From d2e7b1d4390be11add12dd1878a2e2e3ac5d517d Mon Sep 17 00:00:00 2001 From: fukusuket <41001169+fukusuket@users.noreply.github.com> Date: Sun, 9 Mar 2025 20:30:42 +0900 Subject: [PATCH] add rule parser actions --- wela-extractor/src/main.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/wela-extractor/src/main.rs b/wela-extractor/src/main.rs index 5f2c6ad4..7d5b0df3 100644 --- a/wela-extractor/src/main.rs +++ b/wela-extractor/src/main.rs @@ -61,10 +61,10 @@ fn parse_yaml(doc: Yaml, eid_subcategory_pair: &Vec<(String, String)>) -> Option if let Some(logsource) = doc["logsource"].as_hash() { if let Some(service) = logsource.get(&Yaml::from_str("service")) { if service.as_str() == Some("security") { - let uuid = doc["id"].as_str().unwrap_or("No UUID"); - let title = doc["title"].as_str().unwrap_or("No title"); - let desc = doc["description"].as_str().unwrap_or("No description"); - let level = doc["level"].as_str().unwrap_or("No level"); + let uuid = doc["id"].as_str().unwrap_or(""); + let title = doc["title"].as_str().unwrap_or(""); + let desc = doc["description"].as_str().unwrap_or(""); + let level = doc["level"].as_str().unwrap_or(""); let mut event_ids = Vec::new(); extract_event_ids(&doc, &mut event_ids); let mut subcategories = Vec::new();