mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Fix source.ip
This commit is contained in:
@@ -12,7 +12,7 @@ transformations:
|
|||||||
sid: rule.uuid
|
sid: rule.uuid
|
||||||
answer: answers
|
answer: answers
|
||||||
query: dns.query.name
|
query: dns.query.name
|
||||||
src_ip: destination.ip.keyword
|
src_ip: source.ip.keyword
|
||||||
src_port: source.port
|
src_port: source.port
|
||||||
dst_ip: destination.ip.keyword
|
dst_ip: destination.ip.keyword
|
||||||
dst_port: destination.port
|
dst_port: destination.port
|
||||||
|
|||||||
Reference in New Issue
Block a user