Files
blue-team-tools/tools/config/splunk-windows-index.yml
T
2021-07-10 22:23:15 +02:00

13 lines
213 B
YAML

title: Splunk Windows index and EventID field mapping
order: 20
backends:
- splunk
- splunkxml
- splunkdm
logsources:
windows:
product: windows
index: windows
fieldmappings:
EventID: EventCode