Update defaults.yaml

This commit is contained in:
Doug Burks
2023-12-14 13:30:52 -05:00
committed by GitHub
parent 042e5ae9f0
commit 8779fb8cbc

View File

@@ -470,6 +470,18 @@ soc:
- rule.action - rule.action
- rule.reason - rule.reason
- network.community_id - network.community_id
':pfsense:':
- soc_timestamp
- source.ip
- source.port
- destination.ip
- destination.port
- network.transport
- network.direction
- observer.ingress.interface.name
- event.action
- event.reason
- network.community_id
':osquery:': ':osquery:':
- soc_timestamp - soc_timestamp
- source.ip - source.ip