diff --git a/tools/config/stix.yml b/tools/config/stix.yml index fff7f768..c6d13293 100644 --- a/tools/config/stix.yml +++ b/tools/config/stix.yml @@ -43,13 +43,9 @@ fieldmappings: - ipv6-addr:value - network-traffic:dst_ref.value event_data.DestinationPort: - - ipv4-addr:value - - ipv6-addr:value - - network-traffic:dst_ref.value + - network-traffic:dst_port DestinationPort: - - ipv4-addr:value - - ipv6-addr:value - - network-traffic:dst_ref.value + - network-traffic:dst_port event_data.SubjectUserName: - user-account:user_id event_data.User: