mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
FEATURE: Add default columns for endpoint.events datasets #12425
This commit is contained in:
@@ -1001,14 +1001,69 @@ soc:
|
||||
- tds.header_type
|
||||
- log.id.uid
|
||||
- event.dataset
|
||||
':endpoint:events_x_api':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.name
|
||||
- process.Ext.api.name
|
||||
- process.thread.Ext.call_stack_final_user_module.path
|
||||
- event.dataset
|
||||
':endpoint:events_x_file':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.name
|
||||
- event.action
|
||||
- file.path
|
||||
- event.dataset
|
||||
':endpoint:events_x_library':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.name
|
||||
- event.action
|
||||
- dll.path
|
||||
- dll.code_signature.status
|
||||
- dll.code_signature.subject_name
|
||||
- event.dataset
|
||||
':endpoint:events_x_network':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.name
|
||||
- event.action
|
||||
- source.ip
|
||||
- source.port
|
||||
- destination.ip
|
||||
- destination.port
|
||||
- network.community_id
|
||||
- event.dataset
|
||||
':endpoint:events_x_process':
|
||||
- soc_timestamp
|
||||
- event.dataset
|
||||
- host.name
|
||||
- user.name
|
||||
- process.parent.name
|
||||
- process.name
|
||||
- event.action
|
||||
- process.working_directory
|
||||
- event.dataset
|
||||
':endpoint:events_x_registry':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.name
|
||||
- event.action
|
||||
- registry.path
|
||||
- event.dataset
|
||||
':endpoint:events_x_security':
|
||||
- soc_timestamp
|
||||
- host.name
|
||||
- user.name
|
||||
- process.executable
|
||||
- event.action
|
||||
- event.outcome
|
||||
- event.dataset
|
||||
server:
|
||||
bindAddress: 0.0.0.0:9822
|
||||
baseUrl: /
|
||||
|
||||
Reference in New Issue
Block a user