diff --git a/sigma/conversion/base.py b/sigma/conversion/base.py index 32c618c..523e1af 100644 --- a/sigma/conversion/base.py +++ b/sigma/conversion/base.py @@ -1844,6 +1844,9 @@ def convert_correlation_rule_from_template( condition=self.convert_correlation_condition_from_template( rule.condition, rule.rules, correlation_type, method ), + groupby=self.convert_correlation_aggregation_groupby_from_template( + rule.group_by, method + ), ) ]