Update defaults.yaml

This commit is contained in:
bryant-treacle
2023-08-08 15:28:06 -04:00
committed by GitHub
parent bcd1ccd91b
commit 3d4fd08547

View File

@@ -570,14 +570,13 @@ soc:
- destination.geo.country_iso_code - destination.geo.country_iso_code
- user.name - user.name
- source.ip - source.ip
':windows.sysmon_operational:': '::sysmon_operational':
- soc_timestamp - soc_timestamp
- event.action - event.action
- process.executable - winlog.computer_name
- user.name - user.name
- file.target - process.executable
- dns.question.name - process.pid
- winlog.event_data.TargetObject
'::network_connection': '::network_connection':
- soc_timestamp - soc_timestamp
- source.ip - source.ip