Fix poorly formatted data_source sections

This commit is contained in:
pyth0n1c
2024-08-05 15:43:33 -07:00
parent 7a71b722b6
commit fa3d02449f
10 changed files with 10 additions and 20 deletions
+1 -2
View File
@@ -6,5 +6,4 @@ author: Patrick Bareiss, Splunk
description: Data source object for Bro
source: bro:http:json
sourcetype: bro:http:json
supported_TA:
- {}
supported_TA: []
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for CrushFTP
source: crushftp
sourcetype: crushftp:sessionlogs
supported_TA:
- {}
supported_TA: []
fields:
- _time
- _raw
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Kubernetes Audit
source: kubernetes
sourcetype: _json
supported_TA:
- {}
supported_TA: []
fields:
- _time
- annotations.authorization.k8s.io/decision
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Kubernetes Falco
source: kubernetes
sourcetype: kube:container:falco
supported_TA:
- {}
supported_TA: []
fields:
- _time
- command
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Linux Secure
source: /var/log/secure
sourcetype: linux_secure
supported_TA:
- {}
supported_TA: []
fields:
- _time
- action
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Nginx Access
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
supported_TA:
- {}
supported_TA: []
fields:
- _time
- action
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for osquery
source: osquery
sourcetype: osquery:results
supported_TA:
- {}
supported_TA: []
fields:
- _time
- calendarTime
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Powershell Installed IIS Modules
source: powershell://AppCmdModules
sourcetype: Pwsh:InstalledIISModules
supported_TA:
- {}
supported_TA: []
fields:
- _time
- Schema
+1 -2
View File
@@ -6,5 +6,4 @@ author: Patrick Bareiss, Splunk
description: Data source object for Powershell SIP Inventory
source: powershell://SubjectInterfacePackage
sourcetype: PwSh:SubjectInterfacePackage
supported_TA:
- {}
supported_TA: []
+1 -2
View File
@@ -6,8 +6,7 @@ author: Patrick Bareiss, Splunk
description: Data source object for Suricata
source: suricata
sourcetype: suricata
supported_TA:
- {}
supported_TA: []
fields:
- _time
- app_proto