Merge remote-tracking branch 'remotes/origin/dev' into issue/6810

This commit is contained in:
m0duspwnens
2022-01-19 15:35:28 -05:00
4 changed files with 14 additions and 64 deletions

View File

@@ -36,11 +36,11 @@
"@timestamp": {
"type": "date"
},
"kind": {
"so_kind": {
"type": "keyword",
"ignore_above": 1024
},
"operation": {
"so_operation": {
"type": "keyword",
"ignore_above": 1024
},
@@ -48,7 +48,7 @@
"type": "keyword",
"ignore_above": 1024
},
"artifact": {
"so_artifact": {
"properties": {
"artifactType": {
"type": "keyword",
@@ -121,7 +121,7 @@
}
}
},
"artifactstream": {
"so_artifactstream": {
"properties": {
"content": {
"type": "text"
@@ -135,7 +135,7 @@
}
}
},
"case": {
"so_case": {
"properties": {
"assigneeId": {
"type": "keyword",
@@ -193,7 +193,7 @@
}
}
},
"comment": {
"so_comment": {
"properties": {
"caseId": {
"type": "keyword",
@@ -211,7 +211,7 @@
}
}
},
"related": {
"so_related": {
"properties": {
"caseId": {
"type": "keyword",
@@ -220,56 +220,6 @@
"createTime": {
"type": "date"
},
"fields": {
"properties": {
"@timestamp": {
"type": "date"
},
"event": {
"properties": {
"dataset": {
"type": "keyword",
"ignore_above": 1024
},
"module": {
"type": "keyword",
"ignore_above": 1024
},
"category": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"message": {
"type": "text"
},
"scan":{
"type":"object",
"dynamic": true,
"properties":{
"exiftool":{
"type":"text"
},
"pe":{
"properties":{
"sections":{
"properties":{
"entropy":{
"type": "float"
}
}
}
}
}
}
},
"tags": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"userId": {
"type": "keyword",
"ignore_above": 1024