diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 6e86281790..41befe43b5 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,7 +1,7 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 2 -date: '2025-01-23' +version: 3 +date: '2025-06-02' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. @@ -121,6 +121,7 @@ field_mappings: SubjectLogonId: user_logon_id SubjectUserSid: user_sid ShareName: share + Computer: dest - data_model: ocsf mapping: AccessList: access_list @@ -135,6 +136,7 @@ field_mappings: SubjectLogonId: actor.session.uid SubjectUserSid: actor.user.uid ShareName: share + Computer: device.hostname example_log: 5145001281100x80200000000000002018939