mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update winlogbeat.yml
Change Imphash's value as current one does not exist without the Sysmon processor module under Winlogbeat.
This commit is contained in:
parent
99b0d32cec
commit
bdb77780b3
@ -133,7 +133,7 @@ fieldmappings:
|
||||
Image: winlog.event_data.Image
|
||||
ImageLoaded: winlog.event_data.ImageLoaded
|
||||
ImagePath: winlog.event_data.ImagePath
|
||||
Imphash: winlog.event_data.Imphash
|
||||
Imphash: winlog.event_data.Hashes
|
||||
IpAddress: winlog.event_data.IpAddress
|
||||
KeyLength: winlog.event_data.KeyLength
|
||||
LogonProcessName: winlog.event_data.LogonProcessName
|
||||
|
Loading…
Reference in New Issue
Block a user