Files
sigma-rules/etc/non-ecs-schema.json
T
2020-10-29 11:02:29 -08:00

21 lines
318 B
JSON

{
"endgame-*": {
"endgame": {
"metadata": {
"type": "keyword"
},
"event_subtype_full": "keyword"
}
},
"winlogbeat-*": {
"winlog.event_data.OriginalFileName": "keyword"
},
"filebeat-*": {
"zoom": {
"meeting": {
"password": "keyword"
}
}
}
}