Merge pull request #12742 from Security-Onion-Solutions/dougburks-patch-1

FEATURE: Add Events table columns for event.module kratos #12740
This commit is contained in:
Doug Burks
2024-04-03 12:48:24 -04:00
committed by GitHub

View File

@@ -87,12 +87,13 @@ soc:
- log.id.uid
- network.community_id
- event.dataset
':kratos:audit':
':kratos:':
- soc_timestamp
- http_request.headers.x-real-ip
- identity_id
- http_request.headers.user-agent
- event.dataset
- msg
'::conn':
- soc_timestamp
- source.ip