mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Merge pull request #1661 from heyibrahimkhan/patch-2
Create ecs-azure-ad_auditlogs.yml
This commit is contained in:
commit
98165cdd09
11
tools/config/ecs-azure-ad_auditlogs.yml
Normal file
11
tools/config/ecs-azure-ad_auditlogs.yml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
title: Azure AD Audit Logs Elasticsearch ecs mapping
|
||||||
|
order: 20
|
||||||
|
backends:
|
||||||
|
- es-qs
|
||||||
|
- es-rule
|
||||||
|
fieldmappings:
|
||||||
|
category: azure.auditlogs.properties.category
|
||||||
|
activityDisplayName: event.action
|
||||||
|
loggedByService: azure.auditlogs.properties.logged_by_service
|
||||||
|
result: event.outcome
|
||||||
|
initiatedBy.user.userPrincipalName: azure.auditlogs.properties.initiated_by.user.userPrincipalName
|
Loading…
Reference in New Issue
Block a user