Skip to content

Commit 2b5f705

Browse files
committed
upd qradar linux auditd config
1 parent 6973aa3 commit 2b5f705

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed
Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
platform: Qradar
22
source: linux_auditd
3-
description: Text that describe current mapping
3+
description: Auditd field mappings to QRadar default CEPs.
44

55
log_source:
66
devicetype: [11]
@@ -9,8 +9,8 @@ default_log_source:
99
devicetype: 11
1010

1111
field_mapping:
12-
a0: a0
13-
a1: a1
14-
a2: a2
15-
a3: a3
16-
exe: exe
12+
a0: Command
13+
a1: Command
14+
a2: Command
15+
a3: Command
16+
exe: Process Path

0 commit comments

Comments
 (0)