Files
2024-05-22 16:47:39 +00:00

46 lines
696 B
YAML

name: Linux Secure
id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb
author: Patrick Bareiss, Splunk
source: /var/log/secure
sourcetype: linux_secure
supported_TA: {}
event_names: []
fields:
- _time
- action
- app
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- eventtype
- host
- index
- linecount
- pid
- process
- punct
- source
- sourcetype
- splunk_server
- src
- src_port
- sshd_protocol
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- user
- user_name
- vendor_action
- vendor_product
example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael
from 84.202.159.161 port 63487 ssh2'