diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index db98b6b2f..711bba8d6 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -570,6 +570,15 @@ soc: - file.mime_type - log.id.fuid - event.dataset + ':strelka:file': + - soc_timestamp + - file.name + - file.size + - hash.md5 + - file.source + - file.mime_type + - log.id.fuid + - event.dataset ':suricata:': - soc_timestamp - source.ip