Files
blue-team-tools/tools/config/splunk-windows-index.yml
T

12 lines
200 B
YAML
Raw Normal View History

2019-05-16 23:33:51 +02:00
title: Splunk Windows index and EventID field mapping
2019-04-23 00:54:10 +02:00
order: 20
backends:
- splunk
- splunkxml
2018-10-15 15:24:18 +02:00
logsources:
windows:
product: windows
index: windows
fieldmappings:
EventID: EventCode