LogPoint windows mapping

This commit is contained in:
Ben de Haan 2017-03-20 16:57:19 +01:00 committed by GitHub
parent 1bf11dc471
commit c3c405a95e

View File

@ -0,0 +1,20 @@
logsources:
windows-security:
product: windows
service: security
conditions:
event_source: 'Microsoft-Windows-Security-Auditing'
windows-security:
product: windows
service: system
conditions:
event_source: 'Microsoft-Windows-Security-Auditing'
fieldmappings:
EventID: event_id
FailureCode: result_code
GroupName: group_name
ServiceName: service
SubjectAccountName: target_user
TicketOptions: ticket_options
TicketEnctyption: ticket_encryption
Type: event_type