Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

New mappings; Fix mappings; XQL suport datamodel + (preset, dataset)#127

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
saltar-ua merged 1 commit intomainfromgis-xql-datamodel-new-mappings
May 30, 2024
Merged
Show file tree
Hide file tree
Changes fromall commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: aws_cloudtrail
description: Text that describe current mapping


log_source:
table:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: default
description: Text that describe current mapping



default_log_source:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: linux_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: linux_process_creation
description: Text that describe current mapping



default_log_source:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: macos_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: macos_process_creation
description: Text that describe current mapping



default_log_source:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Microsoft Sentinel
source: windows_file_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_image_load
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_process_creation
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_registry_event
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Athena
source: windows_security
description: Text that describe current mapping


default_log_source:
table: eventlog
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,2 @@
platform: Chronicle
source: default
description: Text that describe current mapping
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_create_remote_thread
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_dns_query
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_file_event
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_image_load
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_network_connection
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_pipe_created
description: Text that describe current mapping


field_mapping:
PipeName: target.resource.name
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_process_access
description: Text that describe current mapping


field_mapping:
TargetImage: target.process.file.full_path
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_process_creation
description: Text that describe current mapping



field_mapping:
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_registry_event
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_security
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Chronicle
source: windows_sysmon
description: Text that describe current mapping



field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: default
description: Text that describe current mapping


log_source:
event_simpleName:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: linux_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: macos_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_dns_query
description: Text that describe current mapping


log_source:
event_simpleName: [DnsRequest]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_driver_load
description: Text that describe current mapping


log_source:
event_simpleName: [DriverLoad]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_image_load
description: Text that describe current mapping


log_source:
event_simpleName: [LoadImage]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_network_connection
description: Text that describe current mapping


log_source:
event_simpleName: [NetworkConnectIP4]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_process_creation
description: Text that describe current mapping


log_source:
event_simpleName: [ProcessRollup2]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: Crowdstrike
source: windows_registry_event
description: Text that describe current mapping


log_source:
event_simpleName: [RegistryOperationDetectInfo]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: aws_cloudtrail
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: aws_eks
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_AzureDiagnostics
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_BehaviorAnalytics
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_aadnoninteractiveusersigninlogs
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_azureactivity
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_azuread
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_m365
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: azure_signinlogs
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: default
description: Text that describe current mapping


default_log_source:
index: "*"
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: dns
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: firewall
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: gcp_gcp.audit
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
platform: ElasticSearch
source: gcp_pubsub
description: Text that describe current mapping


log_source:
index: [logs-*]
Expand Down
Loading

[8]ページ先頭

©2009-2025 Movatter.jp