Skip to content

Commit

Permalink
Merge pull request #10986 from Security-Onion-Solutions/fix/windows_e…
Browse files Browse the repository at this point in the history
…vent_table

Fix/windows event table
  • Loading branch information
bryant-treacle authored Aug 8, 2023
2 parents 8455d3d + 036b817 commit 4320dab
Showing 1 changed file with 5 additions and 6 deletions.
11 changes: 5 additions & 6 deletions salt/soc/defaults.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ soc:
- log.id.uid
- network.community_id
- event.dataset
':kratos:kratos.audit':
':kratos:audit':
- soc_timestamp
- http_request.headers.x-real-ip
- identity_id
Expand Down Expand Up @@ -570,14 +570,13 @@ soc:
- destination.geo.country_iso_code
- user.name
- source.ip
':windows.sysmon_operational:':
'::sysmon_operational':
- soc_timestamp
- event.action
- process.executable
- winlog.computer_name
- user.name
- file.target
- dns.question.name
- winlog.event_data.TargetObject
- process.executable
- process.pid
'::network_connection':
- soc_timestamp
- source.ip
Expand Down

0 comments on commit 4320dab

Please sign in to comment.