add opcua_binary_create_session_endpoints to hunt.eventfields.json

This commit is contained in:
Doug Burks
2022-11-25 17:37:10 -05:00
committed by GitHub
parent f36da68009
commit 58aa730437

View File

@@ -78,6 +78,7 @@
"::opcua_binary_browse_response_references": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.node_class", "opcua.display_name_text", "log.id.uid" ], "::opcua_binary_browse_response_references": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.node_class", "opcua.display_name_text", "log.id.uid" ],
"::opcua_binary_browse_result": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.response.link_id", "log.id.uid" ], "::opcua_binary_browse_result": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.response.link_id", "log.id.uid" ],
"::opcua_binary_create_session": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ], "::opcua_binary_create_session": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ],
"::opcua_binary_create_session_endpoints": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.endpoint_link_id", "opcua.endpoint_url", "log.id.uid" ],
"::opcua_binary_create_session_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "log.id.uid" ], "::opcua_binary_create_session_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "log.id.uid" ],
"::opcua_binary_create_subscription": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ], "::opcua_binary_create_subscription": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ],
"::opcua_binary_get_endpoints": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.endpoint_url", "opcua.link_id", "log.id.uid" ], "::opcua_binary_get_endpoints": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.endpoint_url", "opcua.link_id", "log.id.uid" ],