update soc defaults.yaml

This commit is contained in:
Doug Burks
2023-12-19 07:27:07 -05:00
parent 4d8661d2e0
commit ab5de4c104

View File

@@ -469,6 +469,17 @@ soc:
- observer.ingress.interface.name - observer.ingress.interface.name
- event.action - event.action
- network.community_id - network.community_id
':pfsense:':
- soc_timestamp
- source.ip
- source.port
- destination.ip
- destination.port
- network.transport
- network.type
- observer.ingress.interface.name
- event.action
- network.community_id
':osquery:': ':osquery:':
- soc_timestamp - soc_timestamp
- source.ip - source.ip