File tree Expand file tree Collapse file tree 2 files changed +37
-0
lines changed
uncoder-core/app/translator/mappings/platforms/anomali Expand file tree Collapse file tree 2 files changed +37
-0
lines changed Original file line number Diff line number Diff line change
1
+ platform : Anomali
2
+ source : linux_network_connection
3
+
4
+
5
+ log_source :
6
+ product : [linux]
7
+ category : [network_connection]
8
+
9
+ default_log_source :
10
+ product : linux
11
+ category : network_connection
12
+
13
+ field_mapping :
14
+ Image : image
15
+ DestinationHostname : dest
16
+ DestinationIp : dest_ip
17
+ DestinationPort : dest_port
18
+ SourceIp : src_ip
19
+ SourcePort : src_port
20
+ # Initiated: Initiated
Original file line number Diff line number Diff line change
1
+ platform : Anomali
2
+ source : linux_process_creation
3
+
4
+
5
+ log_source :
6
+ product : [linux]
7
+ category : [process_creation]
8
+
9
+ default_log_source :
10
+ product : linux
11
+ category : process_creation
12
+
13
+ field_mapping :
14
+ CommandLine : command_line
15
+ Image : image
16
+ ParentCommandLine : parent_command_line
17
+ ParentImage : parent_image
You can’t perform that action at this time.
0 commit comments