From cdc2ae5ed2a58c7bb5a8e7e43af896259b491663 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Mon, 2 Jun 2025 16:21:05 -0700 Subject: [PATCH] Update windows_event_log_security_5145.yml --- data_sources/windows_event_log_security_5145.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 6e86281790..41befe43b5 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,7 +1,7 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 2 -date: '2025-01-23' +version: 3 +date: '2025-06-02' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. @@ -121,6 +121,7 @@ field_mappings: SubjectLogonId: user_logon_id SubjectUserSid: user_sid ShareName: share + Computer: dest - data_model: ocsf mapping: AccessList: access_list @@ -135,6 +136,7 @@ field_mappings: SubjectLogonId: actor.session.uid SubjectUserSid: actor.user.uid ShareName: share + Computer: device.hostname example_log: 5145001281100x80200000000000002018939