diff --git a/tools/config/sumologic.yml b/tools/config/sumologic.yml index 27355be06..a26d000f8 100644 --- a/tools/config/sumologic.yml +++ b/tools/config/sumologic.yml @@ -2,6 +2,15 @@ title: SumoLogic order: 20 backends: - sumologic +afl_fields: + - _index + - EventID + - CommandLine + - NewProcessName + - Image + - ParentImage + - ParentCommandLine + - ParentProcessName # Sumulogic mapping depends on customer configuration. Adapt to your context! # typically rule on _sourceCategory, _index or Field Extraction Rules (FER) # supposing existing FER for service, EventChannel, EventID