FEATURE: Add Events table columns for event.module strelka #12716

This commit is contained in:
Doug Burks
2024-04-02 10:11:16 -04:00
committed by GitHub
parent 55e71c867c
commit b2b54ccf60

View File

@@ -1894,6 +1894,15 @@ soc:
- event_data.destination.port - event_data.destination.port
- event_data.process.executable - event_data.process.executable
- event_data.process.pid - event_data.process.pid
':strelka:':
- soc_timestamp
- file.name
- file.size
- hash.md5
- file.source
- file.mime_type
- log.id.fuid
- event.dataset
queryBaseFilter: tags:alert queryBaseFilter: tags:alert
queryToggleFilters: queryToggleFilters:
- name: acknowledged - name: acknowledged