mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
LogPoint windows mapping
This commit is contained in:
parent
1bf11dc471
commit
c3c405a95e
20
tools/config/logpoint-windows-all.yml
Normal file
20
tools/config/logpoint-windows-all.yml
Normal file
@ -0,0 +1,20 @@
|
||||
logsources:
|
||||
windows-security:
|
||||
product: windows
|
||||
service: security
|
||||
conditions:
|
||||
event_source: 'Microsoft-Windows-Security-Auditing'
|
||||
windows-security:
|
||||
product: windows
|
||||
service: system
|
||||
conditions:
|
||||
event_source: 'Microsoft-Windows-Security-Auditing'
|
||||
fieldmappings:
|
||||
EventID: event_id
|
||||
FailureCode: result_code
|
||||
GroupName: group_name
|
||||
ServiceName: service
|
||||
SubjectAccountName: target_user
|
||||
TicketOptions: ticket_options
|
||||
TicketEnctyption: ticket_encryption
|
||||
Type: event_type
|
Loading…
Reference in New Issue
Block a user