2019-05-16 21:33:51 +00:00
|
|
|
title: NetWitness
|
2019-04-22 22:54:10 +00:00
|
|
|
order: 20
|
2019-05-19 23:00:33 +00:00
|
|
|
backends:
|
|
|
|
- netwitness
|
2018-10-31 19:07:59 +00:00
|
|
|
logsources:
|
|
|
|
linux:
|
|
|
|
product: linux
|
|
|
|
conditions:
|
|
|
|
device.class: rhlinux
|
|
|
|
linux-sshd:
|
|
|
|
product: linux
|
|
|
|
service: sshd
|
|
|
|
conditions:
|
|
|
|
device.class: rhlinux
|
|
|
|
client: sshd
|
|
|
|
linux-auth:
|
|
|
|
product: linux
|
|
|
|
service: auth
|
|
|
|
conditions:
|
|
|
|
device.class: rhlinux
|
|
|
|
linux-clamav:
|
|
|
|
product: linux
|
|
|
|
service: clamav
|
|
|
|
conditions:
|
|
|
|
device.class: rhlinux
|
|
|
|
windows-sys:
|
|
|
|
product: windows
|
|
|
|
service: sysmon
|
|
|
|
conditions:
|
|
|
|
device.type: winevent_nic
|
|
|
|
event.source: microsoft-windows-security-auditing
|
|
|
|
windows-power:
|
|
|
|
product: windows
|
|
|
|
service: powershell
|
|
|
|
conditions:
|
|
|
|
device.type: winevent_nic
|
2019-02-05 13:35:16 +00:00
|
|
|
windows-dhcp:
|
|
|
|
product: windows
|
|
|
|
service: dhcp
|
2019-12-06 23:23:30 +00:00
|
|
|
conditions:
|
2019-02-05 13:35:16 +00:00
|
|
|
device.type: winevent_nic
|
|
|
|
event.source: microsoft-windows-dhcp-server
|
2018-10-31 19:07:59 +00:00
|
|
|
windows-sec:
|
|
|
|
product: windows
|
|
|
|
service: security
|
|
|
|
conditions:
|
|
|
|
device.type: winevent_nic
|
|
|
|
event.source: microsoft-windows-security-auditing
|
|
|
|
windows-system:
|
|
|
|
product: windows
|
|
|
|
service: system
|
|
|
|
conditions:
|
|
|
|
device.type: winevent_nic
|
|
|
|
fieldmappings:
|
2019-12-06 23:23:30 +00:00
|
|
|
dst:
|
2018-10-31 19:07:59 +00:00
|
|
|
- ip.dst
|
|
|
|
dst_ip:
|
|
|
|
- ip.dst
|
|
|
|
src:
|
|
|
|
- ip.src
|
|
|
|
src_ip:
|
|
|
|
- ip.src
|
|
|
|
DestinationPort:
|
|
|
|
- ip.dstport
|
|
|
|
EventID:
|
|
|
|
- reference.id
|
|
|
|
NewProcessName:
|
|
|
|
- process
|
|
|
|
LogonType:
|
|
|
|
- logon.type
|
|
|
|
AccountName:
|
|
|
|
- user.dst
|
|
|
|
c-uri-extension:
|
|
|
|
- extension
|
2019-12-06 23:23:30 +00:00
|
|
|
c-useragent:
|
2018-10-31 19:07:59 +00:00
|
|
|
- user.agent
|
|
|
|
r-dns:
|
|
|
|
- alias.host
|
|
|
|
DestinationHostname:
|
|
|
|
- alias.host
|
2019-12-06 23:23:30 +00:00
|
|
|
cs-host:
|
2018-10-31 19:07:59 +00:00
|
|
|
- alias.host
|
|
|
|
c-uri-query:
|
|
|
|
- web.page
|
2019-12-06 23:23:30 +00:00
|
|
|
c-uri:
|
2018-10-31 19:07:59 +00:00
|
|
|
- web.page
|
2019-12-06 23:23:30 +00:00
|
|
|
cs-method:
|
2018-10-31 19:07:59 +00:00
|
|
|
- action
|
2019-12-06 23:23:30 +00:00
|
|
|
cs-cookie:
|
2018-10-31 19:07:59 +00:00
|
|
|
- web.cookie
|
|
|
|
SubjectUserName:
|
|
|
|
- user.dst
|