SigmaHQ/tools/config/splunk-windows-index.yml
2020-02-28 16:56:48 +07:00

12 lines
200 B
YAML

title: Splunk Windows index and EventID field mapping
order: 20
backends:
- splunk
- splunkxml
logsources:
windows:
product: windows
index: windows
fieldmappings:
EventID: EventCode