Merge pull request #1295 from findthebad/fix-winlogbeat-config

Updated winlogbeat.yml config to include OriginalFileName
This commit is contained in:
Florian Roth
2020-11-26 23:17:45 +01:00
committed by GitHub
+1
View File
@@ -112,6 +112,7 @@ fieldmappings:
ObjectName: winlog.event_data.ObjectName
ObjectType: winlog.event_data.ObjectType
ObjectValueName: winlog.event_data.ObjectValueName
OriginalFileName: winlog.event_data.OriginalFileName
ParentCommandLine: winlog.event_data.ParentCommandLine
ParentProcessName: winlog.event_data.ParentProcessName
ParentImage: winlog.event_data.ParentImage