add event.dataset since there are other datasets in soc logs

This commit is contained in:
Jason Ertel
2024-05-24 08:38:12 -04:00
parent 15155613c3
commit bd11d59c15

View File

@@ -1273,6 +1273,7 @@ soc:
- observer.ip - observer.ip
':soc:': ':soc:':
- soc_timestamp - soc_timestamp
- event.dataset
- source.ip - source.ip
- soc.fields.requestMethod - soc.fields.requestMethod
- soc.fields.requestPath - soc.fields.requestPath