25dd14829e
Azure Activity Logs Elasticsearch ecs mapping
12 lines
308 B
YAML
12 lines
308 B
YAML
title: Azure Activity Logs Elasticsearch ecs mapping
|
|
order: 20
|
|
backends:
|
|
- es-qs
|
|
- es-rule
|
|
fieldmappings:
|
|
claims.name: user.name
|
|
properties.message: event.action
|
|
properties.eventCategory: azure.activitylogs.event_category
|
|
status.value: event.outcome
|
|
resourceType.value: azure.resource.provider
|