diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index ad154e9d1..f2bf77805 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -502,16 +502,15 @@ soc: - syslog.severity - log.id.uid - event.dataset - '::tunnels': + '::tunnel': - soc_timestamp + - event.dataset - source.ip - source.port - destination.ip - destination.port - - tunnel_type - - action - - log.id.uid - - event.dataset + - event.action + - tunnel.type '::weird': - soc_timestamp - source.ip