Files
blue-team-tools/tools/config/sumologic.yml
T

61 lines
1.3 KiB
YAML
Raw Normal View History

2018-12-09 17:55:51 -05:00
# Sumulogic mapping depends on customer configuration. Adapt to your context!
# typically rule on _sourceCategory, _index or Field Extraction Rules (FER)
# supposing existing FER for service, EventChannel, EventID
logsources:
linux:
product: linux
2018-12-10 22:37:39 +01:00
index: LINUX
2018-12-09 17:55:51 -05:00
linux-sshd:
product: linux
service: sshd
2018-12-10 22:37:39 +01:00
index: LINUX
2018-12-09 17:55:51 -05:00
linux-auth:
product: linux
service: auth
2018-12-10 22:37:39 +01:00
index: LINUX
2018-12-09 17:55:51 -05:00
linux-clamav:
product: linux
service: clamav
2018-12-10 22:37:39 +01:00
index: LINUX
2018-12-09 17:55:51 -05:00
windows:
product: windows
2018-12-10 22:37:39 +01:00
index: WINDOWS
2018-12-09 17:55:51 -05:00
windows-sysmon:
product: windows
service: sysmon
conditions:
EventChannel: Microsoft-Windows-Sysmon
2018-12-10 22:37:39 +01:00
index: WINDOWS
2018-12-09 17:55:51 -05:00
windows-security:
product: windows
service: security
conditions:
EventChannel: Security
2018-12-10 22:37:39 +01:00
index: WINDOWS
2018-12-09 17:55:51 -05:00
windows-powershell:
product: windows
service: powershell
conditions:
EventChannel: Microsoft-Windows-Powershell
2018-12-10 22:37:39 +01:00
index: WINDOWS
2018-12-09 17:55:51 -05:00
windows-system:
product: windows
service: system
conditions:
EventChannel: System
2018-12-10 22:37:39 +01:00
index: WINDOWS
2019-02-05 14:35:16 +01:00
windows-dhcp:
product: windows
service: dhcp
conditions:
EventChannel: Microsoft-Windows-DHCP-Server
index: WINDOWS
2018-12-09 17:55:51 -05:00
apache:
product: apache
service: apache
2018-12-10 22:37:39 +01:00
index: WEBSERVER
2018-12-09 17:55:51 -05:00
firewall:
product: firewall
2018-12-10 22:37:39 +01:00
index: FIREWALL
2018-12-09 17:55:51 -05:00
# if no index, search in all indexes