mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
add endpoint_x_events_x_process to defaults.yaml
This commit is contained in:
@@ -995,6 +995,14 @@ soc:
|
||||
- tds.header_type
|
||||
- log.id.uid
|
||||
- event.dataset
|
||||
':endpoint:endpoint_x_events_x_process':
|
||||
- soc_timestamp
|
||||
- event.dataset
|
||||
- host.name
|
||||
- user.name
|
||||
- process.parent.name
|
||||
- process.name
|
||||
- process.working_directory
|
||||
server:
|
||||
bindAddress: 0.0.0.0:9822
|
||||
baseUrl: /
|
||||
|
||||
Reference in New Issue
Block a user