diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 371a9f2e0..a73c8884d 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -469,6 +469,17 @@ soc: - observer.ingress.interface.name - event.action - network.community_id + ':pfsense:': + - soc_timestamp + - source.ip + - source.port + - destination.ip + - destination.port + - network.transport + - network.type + - observer.ingress.interface.name + - event.action + - network.community_id ':osquery:': - soc_timestamp - source.ip