Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit82d3823

Browse files
authored
Merge pull request#115 from spsocprime/qradar_linux_auditd_upd
upd qradar linux auditd config
2 parents4154275 +1a5d778 commit82d3823

File tree

1 file changed

+11
-6
lines changed

1 file changed

+11
-6
lines changed
Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
platform:Qradar
22
source:linux_auditd
3-
description:Text that describe current mapping
3+
description:Auditd field mappings to QRadar default CEPs.
44

55
log_source:
66
devicetype:[11]
@@ -9,8 +9,13 @@ default_log_source:
99
devicetype:11
1010

1111
field_mapping:
12-
a0:a0
13-
a1:a1
14-
a2:a2
15-
a3:a3
16-
exe:exe
12+
a0:Command
13+
a1:Command
14+
a2:Command
15+
a3:Command
16+
exe:Process Path
17+
CommandLine:Command
18+
Image:Process Path
19+
User:username
20+
LogonId:Logon ID
21+
ParentImage:Parent Process Path

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp