Chainsaw: read a mapping
chainsaw_get_mappingRetrieve Sigma-to-Windows event log mapping details, including groups, filters, and field translations, to diagnose why a Sigma rule is not firing.
Instructions
Describe a Sigma-to-event-log mapping file: groups, filters, field translations.
Mappings decide which Sigma logsources apply to which Windows events. Read this when a Sigma rule you expect is not firing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Mapping file name. Omit for the effective hunt default. | |
| include_yaml | No | Include the full YAML text. |