Merge pull request #12724 from Security-Onion-Solutions/dougburks-patch-1

FEATURE: Add Events table columns for event.module strelka #12716
This commit is contained in:
Doug Burks
2024-04-02 10:15:20 -04:00
committed by GitHub

View File

@@ -1894,6 +1894,15 @@ soc:
- event_data.destination.port
- event_data.process.executable
- event_data.process.pid
':strelka:':
- soc_timestamp
- file.name
- file.size
- hash.md5
- file.source
- file.mime_type
- log.id.fuid
- event.dataset
queryBaseFilter: tags:alert
queryToggleFilters:
- name: acknowledged