mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-02-03 13:53:29 +01:00
Update soc defaults.yaml to include dnp3_control and dnp3_objects eventfields
This commit is contained in:
@@ -212,6 +212,24 @@ soc:
|
||||
- destination.port
|
||||
- dnp3.fc_reply
|
||||
- log.id.uid
|
||||
'::dnp3_control':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
- source.port
|
||||
- destination.ip
|
||||
- destination.port
|
||||
- dnp3.function_code
|
||||
- dnp3.block_type
|
||||
- log.id.uid
|
||||
'::dnp3_objects':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
- source.port
|
||||
- destination.ip
|
||||
- destination.port
|
||||
- dnp3.function_code
|
||||
- dnp3.object_type
|
||||
- log.id.uid
|
||||
'::dns':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
@@ -1415,6 +1433,24 @@ soc:
|
||||
- destination.port
|
||||
- dnp3.fc_reply
|
||||
- log.id.uid
|
||||
'::dnp3_control':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
- source.port
|
||||
- destination.ip
|
||||
- destination.port
|
||||
- dnp3.function_code
|
||||
- dnp3.block_type
|
||||
- log.id.uid
|
||||
'::dnp3_objects':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
- source.port
|
||||
- destination.ip
|
||||
- destination.port
|
||||
- dnp3.function_code
|
||||
- dnp3.object_type
|
||||
- log.id.uid
|
||||
'::dns':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
|
||||
Reference in New Issue
Block a user