mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Updated Winlogbeat Modules config based on: 048c3cc19b/x-pack/winlogbeat/module/powershell/config/winlogbeat-powershell.js (L171-L178)
This commit is contained in:
parent
3926e2388f
commit
1574d263cc
@ -135,7 +135,7 @@ fieldmappings:
|
||||
Product: winlog.event_data.Product
|
||||
Properties: winlog.event_data.Properties
|
||||
RuleName: winlog.event_data.RuleName
|
||||
ScriptBlockText: winlog.event_data.ScriptBlockText
|
||||
ScriptBlockText: powershell.file.script_block_text
|
||||
SecurityID: winlog.event_data.SecurityID
|
||||
ServiceFileName: winlog.event_data.ServiceFileName
|
||||
ServiceName: winlog.event_data.ServiceName
|
||||
|
Loading…
Reference in New Issue
Block a user