mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Merge pull request #1661 from heyibrahimkhan/patch-2
Create ecs-azure-ad_auditlogs.yml
This commit is contained in:
commit
98165cdd09
11
tools/config/ecs-azure-ad_auditlogs.yml
Normal file
11
tools/config/ecs-azure-ad_auditlogs.yml
Normal file
@ -0,0 +1,11 @@
|
||||
title: Azure AD Audit Logs Elasticsearch ecs mapping
|
||||
order: 20
|
||||
backends:
|
||||
- es-qs
|
||||
- es-rule
|
||||
fieldmappings:
|
||||
category: azure.auditlogs.properties.category
|
||||
activityDisplayName: event.action
|
||||
loggedByService: azure.auditlogs.properties.logged_by_service
|
||||
result: event.outcome
|
||||
initiatedBy.user.userPrincipalName: azure.auditlogs.properties.initiated_by.user.userPrincipalName
|
Loading…
Reference in New Issue
Block a user