Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

mappings added and fix 7#148

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
nazargesyk merged 1 commit intoUncoderIO:mainfromrm-socprime:map7
Jun 18, 2024
Merged
Show file tree
Hide file tree
Changes fromall commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,4 +32,5 @@ raw_log_fields:
userIdentity.principalId: object
userIdentity.sessionContext.sessionIssuer.type: object
userIdentity.type: object
userIdentity.userName: object
userIdentity.userName: object
requestParameters.publiclyAccessible: object
View file
Open in desktop
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
platform: Palo Alto XSIAM
source: azure_signinlogs


default_log_source:
dataset: msft_azure_raw

field_mapping:
AppDisplayName: properties.appDisplayName
AppId: properties.appId
AuthenticationRequirement: properties.authenticationRequirement
Category: properties.category
ConditionalAccessStatus: properties.conditionalAccessStatus
DeviceDetail: properties.deviceDetail
IsInteractive: properties.isInteractive
NetworkLocationDetails: properties.networkLocationDetails
ResourceDisplayName: properties.resourceDisplayName
ResourceIdentity: properties.resourceIdentity
ResultDescription: properties.resultDescription
ResultType: properties.resultType
Status.errorCode: properties.status.errorCode
Status: properties.status
Status.failureReason: properties.status.failureReason
TokenIssuerType: properties.tokenIssuerType
UserAgent: properties.userAgent
UserPrincipalName: properties.userPrincipalName

raw_log_fields:
properties.appDisplayName: object
properties.appId: object
properties.authenticationRequirement: object
properties.category: object
properties.conditionalAccessStatus: object
properties.deviceDetail: object
properties.isInteractive: object
properties.networkLocationDetails: object
properties.resourceDisplayName: object
properties.resourceIdentity: object
properties.resultDescription: object
properties.resultType: object
properties.status.errorCode: object
properties.status: object
properties.status.failureReason: object
properties.tokenIssuerType: object
properties.userAgent: object
properties.userPrincipalName: object
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -8,4 +8,6 @@ field_mapping:
dns-query: xdm.network.dns.dns_question.name
dns-answer: xdm.network.dns.dns_resource_record.value
#dns-record: dns-record
dns_query_name: xdm.network.dns.dns_question.name
dns_query_name: xdm.network.dns.dns_question.name
QueryName: xdm.network.dns.dns_question.name
query: xdm.network.dns.dns_question.name
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,3 +14,6 @@ field_mapping:
sc-status: xdm.network.http.response_code
cs-uri-stem: xdm.network.http.url
cs-uri-query: xdm.network.http.url
c-uri-path: xdm.network.http.url
uri_path: xdm.network.http.url
cs-uri: xdm.network.http.url
Original file line numberDiff line numberDiff line change
Expand Up@@ -16,4 +16,5 @@ raw_log_fields:
HostApplication: regex
ContextInfo: regex
HostName: regex
EngineVersion: regex
EngineVersion: regex
Path: regex
Original file line numberDiff line numberDiff line change
Expand Up@@ -147,4 +147,5 @@ raw_log_fields:
ExceptionCode: regex
Service: regex
SamAccountName: regex
ImpersonationLevel: regex
ImpersonationLevel: regex
PrimaryGroupId: regex
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,4 +57,5 @@ raw_log_fields:
FileVersion: regex
StartAddress: regex
StartFunction: regex
EventType: regex
EventType: regex
GrantedAccess: regex
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -20,4 +20,6 @@ raw_log_fields:
param1: regex
param2: regex
Channel: regex
DeviceName: regex
DeviceName: regex
Message: regex
ComputerName: regex
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,7 @@ source: azure_azureactivity

log_source:
product: [azure]
service: [azureactivity]
service: [azureactivity, activitylogs]

default_log_source:
product: azure
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,7 @@ source: azure_azuread

log_source:
product: [azure]
service: [azuread]
service: [azuread, auditlogs]

default_log_source:
product: azure
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,7 @@ source: azure_m365

log_source:
product: [azure]
service: [m365]
service: [m365, o365, office365]

default_log_source:
product: azure
Expand Down

[8]ページ先頭

©2009-2025 Movatter.jp