Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Gis 8070#161

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
tarnopolskyi merged 2 commits intomainfromgis-8070
Jun 27, 2024
Merged
Show file tree
Hide file tree
Changes fromall commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: aws_cloudtrail


log_source:
source_type: [aws:cloudtrail]
sourcetype: [aws:cloudtrail]

default_log_source:
source_type: aws:cloudtrail
sourcetype: aws:cloudtrail

field_mapping:
eventSource: eventSource
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: aws_eks


log_source:
source_type: [aws:*]
sourcetype: [aws:*]

default_log_source:
source_type: aws:*
sourcetype: aws:*

field_mapping:
annotations.authorization.k8s.io\/decision: annotations.authorization.k8s.io\/decision
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_AzureDiagnostics


log_source:
source_type: [azure:*]
sourcetype: [azure:*]

default_log_source:
source_type: azure:*
sourcetype: azure:*

field_mapping:
ResultDescription: ResultDescription
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_BehaviorAnalytics


log_source:
source_type: [azure:*]
sourcetype: [azure:*]

default_log_source:
source_type: azure:*
sourcetype: azure:*

field_mapping:
ActionType: ActionType
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_aadnoninteractiveusersigninlogs


log_source:
source_type: [azure:*]
sourcetype: [azure:*]

default_log_source:
source_type: azure:*
sourcetype: azure:*

field_mapping:
UserAgent: UserAgent
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_azureactivity


log_source:
source_type: [mscs:azure:*, azure:*]
sourcetype: [mscs:azure:*, azure:*]

default_log_source:
source_type: mscs:azure:*
sourcetype: mscs:azure:*

field_mapping:
ActivityStatus: ActivityStatus
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_azuread


log_source:
source_type: [azure:aad:*]
sourcetype: [azure:aad:*]

default_log_source:
source_type: azure:aad:*
sourcetype: azure:aad:*

field_mapping:
ActivityDisplayName: ActivityDisplayName
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: azure_signinlogs


log_source:
source_type: [azure:aad:*]
sourcetype: [azure:aad:*]

default_log_source:
source_type: azure:aad:*
sourcetype: azure:aad:*

field_mapping:
AppDisplayName: AppDisplayName
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,11 +3,11 @@ source: firewall


log_source:
source_type: [fortigate_traffic]
sourcetype: [fortigate_traffic]
index: [fortigate]

default_log_source:
source_type: fortigate_traffic
sourcetype: fortigate_traffic
index: fortigate

field_mapping:
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,7 +3,7 @@ source: gcp_gcp.audit


log_source:
source_type: [google:gcp:*]
sourcetype: [google:gcp:*]

default_log_source:
index: google:gcp:*
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,7 +3,7 @@ source: gcp_pubsub


log_source:
source_type: [google:gcp:*]
sourcetype: [google:gcp:*]

default_log_source:
index: google:gcp:*
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: linux_auditd


log_source:
source_type: [linux:audit]
sourcetype: [linux:audit]

default_log_source:
source_type: linux:audit
sourcetype: linux:audit

field_mapping:
a0: a0
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: okta_okta


log_source:
source_type: [OktaIM2:*]
sourcetype: [OktaIM2:*]

default_log_source:
source_type: OktaIM2:*
sourcetype: OktaIM2:*

field_mapping:
client.user.id: client.user.id
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,10 @@ platform: Splunk
source: windows_bits_client

log_source:
source_type: [XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational]

default_log_source:
source_type: XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational

field_mapping:
LocalName: LocalName
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_dns_query

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
Image: Image
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_driver_load

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
ImageLoaded: ImageLoaded
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_access

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_change

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_create

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_delete

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_event

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_file_rename

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CreationUtcTime: CreationUtcTime
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_image_load

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
Image: Image
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: windows_ldap_debug


log_source:
source_type: [XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug]
sourcetype: [XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug]

default_log_source:
source_type: XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug
sourcetype: XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug

field_mapping:
EventID: EventID
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_network_connection

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
Image: Image
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: windows_ntlm


log_source:
source_type: [XmlWinEventLog:Microsoft-Windows-NTLM/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-NTLM/Operational]

default_log_source:
source_type: XmlWinEventLog:Microsoft-Windows-NTLM/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-NTLM/Operational

field_mapping:
WorkstationName: WorkstationName
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,11 +4,11 @@ source: windows_registry_event

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
TargetObject: TargetObject
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,11 +3,11 @@ source: windows_sysmon

log_source:
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]

default_log_source:
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

field_mapping:
CommandLine: CommandLine
Expand Down
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,10 +3,10 @@ source: windows_wmi_event


log_source:
source_type: [XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational]
sourcetype: [XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational]

default_log_source:
source_type: XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational
sourcetype: XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational

field_mapping:
Destination: Destination
Expand Down
4 changes: 2 additions & 2 deletionsuncoder-core/app/translator/platforms/splunk/mapping.py
View file
Open in desktop
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ def prepare_log_source_signature(self, mapping: dict) -> SplunkLogSourceSignatur
default_log_source = mapping["default_log_source"]
return SplunkLogSourceSignature(
sources=log_source.get("source"),
source_types=log_source.get("source_type"),
source_categories=log_source.get("source_category"),
source_types=log_source.get("sourcetype"),
source_categories=log_source.get("sourcecategory"),
indices=log_source.get("index"),
default_source=default_log_source,
)
Expand Down

[8]ページ先頭

©2009-2025 Movatter.jp