To avoid confuse ,Unified quote of profile file in config folder to double quote #165
This commit is contained in:
@@ -1,14 +1,14 @@
|
||||
---
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
Level: '%Level%'
|
||||
EventID: '%EventID%'
|
||||
MitreAttack: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
RecordInformation: '%RecordInformation%'
|
||||
RuleFile: '%RuleFile%'
|
||||
EvtxFile: '%EvtxFile%'
|
||||
Tags: '%MitreAttack%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
Level: "%Level%"
|
||||
EventID: "%EventID%"
|
||||
MitreAttack: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
RecordInformation: "%RecordInformation%"
|
||||
RuleFile: "%RuleFile%"
|
||||
EvtxFile: "%EvtxFile%"
|
||||
Tags: "%MitreAttack%"
|
||||
@@ -1,44 +1,44 @@
|
||||
minimal:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
|
||||
default:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
|
||||
verbose-1:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
RulePath: '%RulePath%'
|
||||
FilePath: '%FilePath%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
RulePath: "%RulePath%"
|
||||
FilePath: "%FilePath%"
|
||||
|
||||
verbose-2:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
AllFieldInfo: '%RecordInformation%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
AllFieldInfo: "%RecordInformation%"
|
||||
@@ -1,13 +1,13 @@
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
Level: '%Level%'
|
||||
EventID: '%EventID%'
|
||||
MitreAttack: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
RecordInformation: '%RecordInformation%'
|
||||
RuleFile: '%RuleFile%'
|
||||
EvtxFile: '%EvtxFile%'
|
||||
Tags: '%MitreAttack%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
Level: "%Level%"
|
||||
EventID: "%EventID%"
|
||||
MitreAttack: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
RecordInformation: "%RecordInformation%"
|
||||
RuleFile: "%RuleFile%"
|
||||
EvtxFile: "%EvtxFile%"
|
||||
Tags: "%MitreAttack%"
|
||||
|
||||
@@ -1,44 +1,44 @@
|
||||
minimal:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
|
||||
default:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
|
||||
verbose-1:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
RulePath: '%RulePath%'
|
||||
FilePath: '%FilePath%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
RulePath: "%RulePath%"
|
||||
FilePath: "%FilePath%"
|
||||
|
||||
verbose-2:
|
||||
Timestamp: '%Timestamp%'
|
||||
Computer: '%Computer%'
|
||||
Channel: '%Channel%'
|
||||
EventID: '%EventID%'
|
||||
Level: '%Level%'
|
||||
Tags: '%MitreAttack%'
|
||||
RecordID: '%RecordID%'
|
||||
RuleTitle: '%RuleTitle%'
|
||||
Details: '%Details%'
|
||||
AllFieldInfo: '%RecordInformation%'
|
||||
Timestamp: "%Timestamp%"
|
||||
Computer: "%Computer%"
|
||||
Channel: "%Channel%"
|
||||
EventID: "%EventID%"
|
||||
Level: "%Level%"
|
||||
Tags: "%MitreAttack%"
|
||||
RecordID: "%RecordID%"
|
||||
RuleTitle: "%RuleTitle%"
|
||||
Details: "%Details%"
|
||||
AllFieldInfo: "%RecordInformation%"
|
||||
Reference in New Issue
Block a user