SigmaHQ/tools/config/splunk-windows-index.yml
2019-07-14 00:50:15 +02:00

12 lines
200 B
YAML

title: Splunk Windows index and EventID field mapping
order: 20
backends:
- splunk
- splunkxml
logsources:
windows:
product: windows
index: windows
fieldmappings:
EventID: EventCode