Merge pull request #1295 from findthebad/fix-winlogbeat-config
Updated winlogbeat.yml config to include OriginalFileName
This commit is contained in:
@@ -112,6 +112,7 @@ fieldmappings:
|
||||
ObjectName: winlog.event_data.ObjectName
|
||||
ObjectType: winlog.event_data.ObjectType
|
||||
ObjectValueName: winlog.event_data.ObjectValueName
|
||||
OriginalFileName: winlog.event_data.OriginalFileName
|
||||
ParentCommandLine: winlog.event_data.ParentCommandLine
|
||||
ParentProcessName: winlog.event_data.ParentProcessName
|
||||
ParentImage: winlog.event_data.ParentImage
|
||||
|
||||
Reference in New Issue
Block a user