mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
WIP
This commit is contained in:
@@ -29,4 +29,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- displayMessage
|
||||
- client.geographicalContext.country
|
||||
- client.geographicalContext.state
|
||||
- client.geographicalContext.city
|
||||
security_domain: access
|
||||
|
||||
@@ -29,4 +29,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- displayMessage
|
||||
- app
|
||||
- user
|
||||
- result
|
||||
- src_ip
|
||||
security_domain: access
|
||||
|
||||
@@ -35,4 +35,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- displayMessage
|
||||
- client.geographicalContext.city
|
||||
- client.geographicalContext.state
|
||||
- user
|
||||
security_domain: access
|
||||
|
||||
@@ -39,4 +39,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest_category
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -47,6 +47,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.object_category
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 10
|
||||
|
||||
@@ -48,6 +48,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.object_category
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 40
|
||||
|
||||
@@ -46,6 +46,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.command
|
||||
- All_Changes.user
|
||||
- All_Changes.status
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 25
|
||||
|
||||
@@ -47,6 +47,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.command
|
||||
- All_Changes.object_category
|
||||
- All_Changes.status
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 25
|
||||
|
||||
@@ -50,6 +50,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Authentication.signature
|
||||
- Authentication.vendor_account
|
||||
- Authentication.user
|
||||
- Authentication.user_role
|
||||
- Authentication.src
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 15
|
||||
|
||||
@@ -38,4 +38,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventID
|
||||
- awsRegion
|
||||
- requestParameters.policy
|
||||
- userIdentity.principalId
|
||||
security_domain: threat
|
||||
|
||||
@@ -33,4 +33,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- requestParameters.x-amz-server-side-encryption
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.x-amz-copy-source
|
||||
- requestParameters.key
|
||||
- userAgent
|
||||
- region
|
||||
security_domain: threat
|
||||
|
||||
@@ -44,6 +44,18 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- requestParameters.ruleAction
|
||||
- requestParameters.egress
|
||||
- requestParameters.aclProtocol
|
||||
- requestParameters.portRange.to
|
||||
- requestParameters.portRange.from
|
||||
- requestParameters.cidrBlock
|
||||
- userName
|
||||
- userIdentity.principalId
|
||||
- userAgent
|
||||
risk_object: userName
|
||||
risk_object_type: user
|
||||
risk_score: 10
|
||||
|
||||
@@ -40,6 +40,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- requestParameters.egress
|
||||
- userName
|
||||
- userIdentity.principalId
|
||||
- src
|
||||
- userAgent
|
||||
risk_object: userName
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -40,4 +40,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- requestParameters.principalArn
|
||||
- requestParameters.roleArn
|
||||
- requestParameters.roleSessionName
|
||||
- recipientAccountId
|
||||
- responseElements.issuer
|
||||
- sourceIPAddress
|
||||
- userAgent
|
||||
security_domain: threat
|
||||
|
||||
@@ -36,4 +36,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- eventType
|
||||
- requestParameters.sAMLProviderArn
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- sourceIPAddress
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.principalId
|
||||
security_domain: threat
|
||||
|
||||
@@ -44,6 +44,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.user
|
||||
- All_Changes.user_type
|
||||
- All_Changes.status
|
||||
- All_Changes.command
|
||||
- All_Changes.object
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 25
|
||||
|
||||
@@ -42,6 +42,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object
|
||||
- All_Changes.action
|
||||
- All_Changes.user
|
||||
- All_Changes.vendor_region
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
|
||||
@@ -48,6 +48,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.vendor_region
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
|
||||
@@ -43,6 +43,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.Instance_Changes.image_id
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
|
||||
+6
@@ -43,6 +43,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.Instance_Changes.instance_type
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
|
||||
@@ -43,6 +43,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.command
|
||||
- All_Changes.action
|
||||
- All_Changes.change_type
|
||||
- All_Changes.status
|
||||
- All_Changes.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 10
|
||||
|
||||
@@ -58,6 +58,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.src
|
||||
- All_Changes.user
|
||||
- All_Changes.object
|
||||
- All_Changes.command
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 10
|
||||
|
||||
@@ -58,6 +58,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.src
|
||||
- All_Changes.user
|
||||
- All_Changes.object
|
||||
- All_Changes.command
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -57,6 +57,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.object_id
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.src
|
||||
- All_Changes.user
|
||||
- All_Changes.command
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -58,6 +58,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.action
|
||||
- All_Changes.status
|
||||
- All_Changes.src
|
||||
- All_Changes.user
|
||||
- All_Changes.object
|
||||
- All_Changes.command
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -48,6 +48,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Authentication.signature
|
||||
- Authentication.user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 30
|
||||
|
||||
@@ -56,6 +56,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Authentication.signature
|
||||
- Authentication.user
|
||||
- Authentication.src
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -56,6 +56,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Authentication.signature
|
||||
- Authentication.user
|
||||
- Authentication.src
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -56,6 +56,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Authentication.signature
|
||||
- Authentication.user
|
||||
- Authentication.src
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 5
|
||||
|
||||
@@ -54,4 +54,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- sc_status_
|
||||
- cs_object_
|
||||
- c_ip_
|
||||
- cs_uri_
|
||||
- cs_method_
|
||||
security_domain: network
|
||||
|
||||
@@ -42,4 +42,15 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- data.resource.type
|
||||
- data.protoPayload.methodName
|
||||
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action
|
||||
- data.protoPayload.authenticationInfo.principalEmail
|
||||
- data.protoPayload.resourceLocation.currentLocations{}
|
||||
- data.protoPayload.requestMetadata.callerIp
|
||||
- data.protoPayload.resourceName
|
||||
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role
|
||||
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member
|
||||
security_domain: network
|
||||
|
||||
@@ -43,6 +43,16 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventSource
|
||||
- eventName
|
||||
- requestParameters.bucketName
|
||||
- userName
|
||||
- userIdentity.principalId
|
||||
- userAgent
|
||||
- uri
|
||||
- permission
|
||||
risk_object: src
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
|
||||
@@ -44,6 +44,19 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventSource
|
||||
- eventName
|
||||
- requestParameters.accessControlList.x-amz-grant-read-acp
|
||||
- requestParameters.accessControlList.x-amz-grant-write
|
||||
- requestParameters.accessControlList.x-amz-grant-write-acp
|
||||
- requestParameters.accessControlList.x-amz-grant-full-control
|
||||
- requestParameters.bucketName
|
||||
- userName
|
||||
- userIdentity.principalId
|
||||
- userAgent
|
||||
- bucketName
|
||||
risk_object: src
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
|
||||
@@ -43,6 +43,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- http_status
|
||||
- bucket_name
|
||||
- remote_ip
|
||||
risk_object: src_ip
|
||||
risk_object_type: system
|
||||
risk_score: 10
|
||||
|
||||
@@ -36,4 +36,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Resources{}.Type
|
||||
- Title
|
||||
- Types{}
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
- severity
|
||||
- dest
|
||||
security_domain: network
|
||||
|
||||
@@ -31,4 +31,9 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- findings{}.Resources{}.Type
|
||||
- indings{}.Resources{}.Id
|
||||
- user
|
||||
security_domain: network
|
||||
|
||||
@@ -59,6 +59,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- action
|
||||
- src_ip
|
||||
- dest_ip
|
||||
risk_object: src_ip
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
|
||||
@@ -52,6 +52,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- eventName
|
||||
- userIdentity.arn
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 10
|
||||
|
||||
@@ -33,4 +33,16 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Operation
|
||||
- record_type
|
||||
- app
|
||||
- user
|
||||
- LogonError
|
||||
- authentication_method
|
||||
- signature
|
||||
- UserAgent
|
||||
- src_ip
|
||||
- record_type
|
||||
security_domain: threat
|
||||
|
||||
@@ -36,4 +36,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Workload
|
||||
- Operation
|
||||
- Actor{}.ID
|
||||
- Actor{}.Type
|
||||
- ActorIpAddress
|
||||
- dest
|
||||
- ResultStatus
|
||||
security_domain: threat
|
||||
|
||||
@@ -39,4 +39,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Workload
|
||||
- signature
|
||||
- Actor{}.ID
|
||||
- ModifiedProperties{}.Name
|
||||
- ModifiedProperties{}.NewValue
|
||||
- Target{}.ID
|
||||
- ActorIpAddress
|
||||
security_domain: threat
|
||||
|
||||
@@ -39,4 +39,16 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- signature
|
||||
- ModifiedProperties{}.Name
|
||||
- ModifiedProperties{}.NewValue
|
||||
- ModifiedProperties{}.OldValue
|
||||
- user
|
||||
- vendor_product
|
||||
- vendor_account
|
||||
- status
|
||||
- user_id
|
||||
- action
|
||||
security_domain: threat
|
||||
|
||||
@@ -32,4 +32,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Operation
|
||||
- UserType
|
||||
- user
|
||||
- status
|
||||
- signature
|
||||
- dest
|
||||
- ResultStatus
|
||||
security_domain: threat
|
||||
|
||||
@@ -33,4 +33,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Workload
|
||||
- UserAuthenticationMethod
|
||||
- status
|
||||
- UserAgent
|
||||
- src_ip
|
||||
- user
|
||||
security_domain: threat
|
||||
|
||||
@@ -34,4 +34,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Workload
|
||||
- LogonError
|
||||
- ActorIpAddress
|
||||
- UserAgent
|
||||
- UserId
|
||||
security_domain: threat
|
||||
|
||||
@@ -38,4 +38,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Workload
|
||||
- Operation
|
||||
- Parameters{}.Value
|
||||
- ObjectId
|
||||
- OrganizationName
|
||||
- OriginatingServer
|
||||
- UserId
|
||||
- UserKey
|
||||
security_domain: threat
|
||||
|
||||
@@ -33,4 +33,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Category
|
||||
- Name
|
||||
- Source
|
||||
- Severity
|
||||
- AlertEntityId
|
||||
- Operation
|
||||
security_domain: threat
|
||||
|
||||
@@ -35,4 +35,8 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
security_domain: threat
|
||||
|
||||
@@ -35,4 +35,8 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
security_domain: threat
|
||||
|
||||
@@ -35,4 +35,8 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
security_domain: threat
|
||||
|
||||
+2
@@ -57,4 +57,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
security_domain: network
|
||||
+3
@@ -30,4 +30,7 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
-
|
||||
security_domain: threat
|
||||
+2
@@ -41,4 +41,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
security_domain: threat
|
||||
@@ -40,4 +40,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventCode
|
||||
- TargetImage
|
||||
- CallTrace
|
||||
- Computer
|
||||
- TargetProcessId
|
||||
- SourceImage
|
||||
- SourceProcessId
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -45,4 +45,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
|
||||
+6
@@ -45,4 +45,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Registry.registry_path
|
||||
- Registry.registry_key_name
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -52,4 +52,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -42,4 +42,9 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -46,4 +46,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Filesystem.dest
|
||||
- Filesystem.file_name
|
||||
- Filesystem.user
|
||||
- Filesystem.file_path
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -41,4 +41,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -33,4 +33,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -57,4 +57,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Filesystem.user
|
||||
- Filesystem.dest
|
||||
- Filesystem.file_path
|
||||
- Filesystem.file_name
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -43,4 +43,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Filesystem.user
|
||||
- Filesystem.dest
|
||||
- Filesystem.file_path
|
||||
- Filesystem.file_name
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -44,4 +44,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -43,4 +43,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processs.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -40,4 +40,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- TargetImage
|
||||
- Computer
|
||||
- EventCode
|
||||
- TargetImage
|
||||
- TargetProcessId
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -46,4 +46,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- TargetFilename
|
||||
- Computer
|
||||
- object_category
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -43,4 +43,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -39,4 +39,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -42,4 +42,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -40,4 +40,13 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -48,4 +48,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -41,4 +41,12 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventCode
|
||||
- Logon_Type
|
||||
- Logon_Process
|
||||
- WorkstationName
|
||||
- user
|
||||
- dest
|
||||
security_domain: access
|
||||
|
||||
@@ -37,4 +37,11 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventCode
|
||||
- TargetUserName
|
||||
- LogonType
|
||||
- TargetDomainName
|
||||
- user
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -47,4 +47,14 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventCode
|
||||
- TargetImage
|
||||
- GrantedAccess
|
||||
- Computer
|
||||
- SourceImage
|
||||
- SourceProcessId
|
||||
- TargetImage
|
||||
- TargetProcessId
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -49,4 +49,10 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- All_Changes.user
|
||||
- nodename
|
||||
- All_Changes.result
|
||||
- All_Changes.dest
|
||||
security_domain: access
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user