Skip to content

Commit 4536c50

Browse files
committed
new fields
1 parent 9eed876 commit 4536c50

File tree

2 files changed

+19
-1
lines changed

2 files changed

+19
-1
lines changed

uncoder-core/app/translator/mappings/platforms/palo_alto_cortex/default.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@ field_mapping:
4646
c-uri-query: xdm.network.http.url
4747
QueryName: xdm.network.dns.dns_question.name
4848
Application: xdm.network.application_protocol
49+
sourceNetwork: xdm.source.subnet
4950
SourceHostName: xdm.source.host.hostname
5051
DestinationHostname: xdm.target.host.hostname
5152
Hashes:
@@ -127,3 +128,9 @@ field_mapping:
127128
url_category: xdm.network.http.url_category
128129
EventSeverity: xdm.alert.severity
129130
duration: xdm.event.duration
131+
ThreatName: xdm.alert.original_threat_id
132+
AnalyzerName: xdm.observer.type
133+
Classification: xdm.alert.category
134+
ResultCode: xdm.event.outcome_reason
135+
Technique: xdm.alert.mitre_techniques
136+
Action: xdm.event.outcome

uncoder-core/app/translator/mappings/platforms/qradar/default.yml

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,7 @@ field_mapping:
1919
src-port:
2020
- SourcePort
2121
- localport
22+
- sourcePort
2223
src-ip:
2324
- sourceip
2425
- source_ip
@@ -34,13 +35,15 @@ field_mapping:
3435
User:
3536
- userName
3637
- EventUserName
38+
- Alert Threat Cause Actor Name
3739
CommandLine: Command
3840
Protocol:
3941
- IPProtocol
4042
- protocol
4143
Application:
4244
- Application
4345
- application
46+
sourceNetwork: sourceNetwork
4447
SourceHostName:
4548
- HostCount-source
4649
- identityHostName
@@ -78,4 +81,12 @@ field_mapping:
7881
Source:
7982
- Source
8083
- source
81-
duration: duration
84+
duration: duration
85+
ThreatName:
86+
- Threat Name
87+
- Alert Blocked Threat Category
88+
AnalyzerName: Analyzer Name
89+
Classification: Classification
90+
ResultCode: Alert Reason Code
91+
Technique: Technique
92+
Action: Action

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy