Skip to content

Commit 31edd63

Browse files
authored
Merge pull request #143 from UncoderIO/gis-aql-upd-13-06-2024
mappings improvement from 7989
2 parents 899e9e9 + fa0e8b7 commit 31edd63

File tree

2 files changed

+17
-2
lines changed

2 files changed

+17
-2
lines changed

uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -118,3 +118,7 @@ field_mapping:
118118
SubjectAccountName: xdm.source.user.username
119119
ComputerName: xdm.source.host.hostname
120120
ExternalSeverity: xdm.alert.severity
121+
SourceMAC: xdm.source.host.mac_addresses
122+
DestinationMAC: xdm.target.host.mac_addresses
123+
SourceOS: xdm.source.host.os
124+
DestinationOS: xdm.target.host.os

uncoder-core/app/translator/mappings/platforms/qradar/default.yml

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ default_log_source:
99

1010
field_mapping:
1111
icmp.type: IcmpType
12+
icmp.code: IcmpCode
1213
dst-port:
1314
- DstPort
1415
- DestinationPort
@@ -26,7 +27,9 @@ field_mapping:
2627
- destination_ip
2728
- destinationIP
2829
- destinationaddress
29-
User: userName
30+
User:
31+
- userName
32+
- EventUserName
3033
CommandLine: Command
3134
Protocol: IPProtocol
3235
Application:
@@ -47,4 +50,12 @@ field_mapping:
4750
- dst-packets
4851
src-bytes: src-bytes
4952
dst-bytes: dst-bytes
50-
ExternalSeverity: External Severity
53+
ExternalSeverity: External Severity
54+
SourceMAC:
55+
- SourceMAC
56+
- MAC
57+
DestinationMAC: DestinationMAC
58+
SourceOS:
59+
- SourceOS
60+
- OS
61+
DestinationOS: DestinationOS

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy