EXTRACT_EVIDENCE
- Last Updated: May 13, 2026
- 1 minute read
- Semaphore
- Documentation
When the EXTRACT_EVIDENCE attribute is set the rule will mark all its evidence for possible extraction by a parent rule with EXTRACT attribute set.
In most cases the EXTRACT_NAME attribute should be used instead which has the same behaviour for most rules. However when extracting EXPRESSION rules the EXTRACT_NAME will capture the normalised form of the zone (if given). If you want to extract the actual evidence (un-normalised) then use this attribute instead.
Applies to
No restriction on which rule it may be applied to.
Values
- “XXXX” - XXXX is the name given to the extracted evidence.