mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Update defaults.yaml
This commit is contained in:
@@ -570,14 +570,13 @@ soc:
|
||||
- destination.geo.country_iso_code
|
||||
- user.name
|
||||
- source.ip
|
||||
':windows.sysmon_operational:':
|
||||
'::sysmon_operational':
|
||||
- soc_timestamp
|
||||
- event.action
|
||||
- process.executable
|
||||
- winlog.computer_name
|
||||
- user.name
|
||||
- file.target
|
||||
- dns.question.name
|
||||
- winlog.event_data.TargetObject
|
||||
- process.executable
|
||||
- process.pid
|
||||
'::network_connection':
|
||||
- soc_timestamp
|
||||
- source.ip
|
||||
|
||||
Reference in New Issue
Block a user