mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
SOCtopus - Edit osquery playbook template
Fixes bug for when there is no [osquery][columns][address] field
This commit is contained in:
@@ -45,4 +45,3 @@ hive_observable_data_mapping:
|
||||
- ip: '{match[osquery][EndpointIP2]}'
|
||||
- other: '{match[osquery][hostIdentifier]}'
|
||||
- other: '{match[osquery][hostname]}'
|
||||
- ip: '{match[osquery][columns][address]}'
|
||||
|
||||
Reference in New Issue
Block a user