mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
add opcua_binary_get_endpoints_description to hunt.eventfields.json
This commit is contained in:
@@ -80,6 +80,7 @@
|
|||||||
"::opcua_binary_create_session": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ],
|
"::opcua_binary_create_session": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "log.id.uid" ],
|
||||||
"::opcua_binary_create_session_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "log.id.uid" ],
|
"::opcua_binary_create_session_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "log.id.uid" ],
|
||||||
"::opcua_binary_get_endpoints": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.endpoint_url", "opcua.link_id", "log.id.uid" ],
|
"::opcua_binary_get_endpoints": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.endpoint_url", "opcua.link_id", "log.id.uid" ],
|
||||||
|
"::opcua_binary_get_endpoints_description": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.text", "opcua.product_uri", "log.id.uid" ],
|
||||||
"::opcua_binary_get_endpoints_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "opcua.user_token.type", "log.id.uid" ],
|
"::opcua_binary_get_endpoints_user_token": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.user_token.link_id", "opcua.user_token.type", "log.id.uid" ],
|
||||||
"::opcua_binary_read": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "opcua.read_results.link_id", "log.id.uid" ],
|
"::opcua_binary_read": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.link_id", "opcua.read_results.link_id", "log.id.uid" ],
|
||||||
"::opcua_binary_status_code_detail": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.info_type_string", "opcua.source_string", "log.id.uid" ],
|
"::opcua_binary_status_code_detail": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "opcua.info_type_string", "opcua.source_string", "log.id.uid" ],
|
||||||
|
|||||||
Reference in New Issue
Block a user