FEATURE: Add SOC default fields for iptables logs #14836

This commit is contained in:
Doug Burks
2025-07-14 12:04:46 -04:00
committed by GitHub
parent 3108556495
commit f8108e93d5

View File

@@ -1336,6 +1336,13 @@ soc:
- soc.fields.statusCode
- event.action
- soc.fields.error
':iptables:':
- soc_timestamp
- source.ip
- source.port
- destination.ip
- destination.port
- message
server:
bindAddress: 0.0.0.0:9822
baseUrl: /