SigmaHQ/tools/config/splunk-windows-index.yml

12 lines
200 B
YAML
Raw Normal View History

2019-05-16 21:33:51 +00:00
title: Splunk Windows index and EventID field mapping
2019-04-22 22:54:10 +00:00
order: 20
backends:
- splunk
- splunkxml
logsources:
windows:
product: windows
index: windows
fieldmappings:
EventID: EventCode