Merge pull request #239 from neu5ron/master

update helk config
This commit is contained in:
Florian Roth
2019-02-05 20:01:28 +01:00
committed by GitHub
+3 -3
View File
@@ -48,11 +48,11 @@ fieldmappings:
Destination:
EventID=20: wmi_consumer_destination
DestinationHostname: dst_host_name
DestinationIp: dst_ip
DestinationIp: dst_ip_addr
DestinationIsIpv6: dst_is_ipv6
DestinationPort: dst_port
DestinationPortName: dst_port_name
Details:
Details:
EventID=13: registry_key_value
Device: device_name
EngineVersion: powershell.engine.version
@@ -130,7 +130,7 @@ fieldmappings:
State:
EventID=4: service_state
EventID=16: sysmon_configuration_state
SubjectUserName:
SubjectUserName:
EventID=4624: user_reporter_name
EventId=4648: user_name
EventID=5140: user_name