Use module in dataset name and add dataset tag

This commit is contained in:
Wes
2023-06-15 13:06:57 +00:00
parent 03082339ca
commit b5bccc5e05
4 changed files with 114 additions and 109 deletions

View File

@@ -5,7 +5,7 @@ elasticsearch_host: "{{ GLOBALS.url_base }}:9200"
play_title: ""
play_id: ""
event.module: "playbook"
event.dataset: "alert"
event.dataset: "playbook.alert"
event.severity:
rule.category:
play_url: "https://{{ GLOBALS.url_base }}/playbook/issues/6000"