Merge pull request #12667 from Security-Onion-Solutions/dougburks-patch-1

FEATURE: Add Events table columns for event.module elastic_agent #12666
This commit is contained in:
Doug Burks
2024-03-26 16:11:46 -04:00
committed by GitHub

View File

@@ -1176,6 +1176,10 @@ soc:
- logdata.USERNAME
- logdata.USERAGENT
- event.dataset
':elastic_agent:':
- soc_timestamp
- event.dataset
- message
server:
bindAddress: 0.0.0.0:9822
baseUrl: /