From 5db3e223632f8890b0724a7700ae0ce1a439caad Mon Sep 17 00:00:00 2001 From: Wes Date: Tue, 29 Nov 2022 19:58:18 +0000 Subject: [PATCH] Add s7comm_upload_download references in various places --- salt/soc/files/soc/hunt.eventfields.json | 2 ++ 1 file changed, 2 insertions(+) diff --git a/salt/soc/files/soc/hunt.eventfields.json b/salt/soc/files/soc/hunt.eventfields.json index 0b452df14..c7abb6e75 100644 --- a/salt/soc/files/soc/hunt.eventfields.json +++ b/salt/soc/files/soc/hunt.eventfields.json @@ -99,6 +99,8 @@ "::profinet_dce_rpc": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "profinet.operation", "log.id.uid" ], "::s7comm": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.ros.control.name", "s7.function.name", "log.id.uid" ], "::s7comm_plus": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.opcode.name", "s7.version", "log.id.uid" ], + "::s7comm_read_szl": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.szl_id_name", "s7.return_code_name", "log.id.uid" ], + "::s7comm_upload_download": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.ros.control.name", "s7.function_code", "log.id.uid" ], "::tds": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.command", "log.id.uid", "event.dataset" ], "::tds_rpc": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.procedure_name", "log.id.uid", "event.dataset" ], "::tds_sql_batch": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.header_type", "log.id.uid", "event.dataset" ]