Skip to content

Commit 95e0b6e

Browse files
authored
Merge pull request #161 from UncoderIO/gis-8070
Gis 8070
2 parents 5a15552 + 1b5cfdf commit 95e0b6e

30 files changed

+58
-58
lines changed

uncoder-core/app/translator/mappings/platforms/splunk/aws_cloudtrail.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: aws_cloudtrail
33

44

55
log_source:
6-
source_type: [aws:cloudtrail]
6+
sourcetype: [aws:cloudtrail]
77

88
default_log_source:
9-
source_type: aws:cloudtrail
9+
sourcetype: aws:cloudtrail
1010

1111
field_mapping:
1212
eventSource: eventSource

uncoder-core/app/translator/mappings/platforms/splunk/aws_eks.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: aws_eks
33

44

55
log_source:
6-
source_type: [aws:*]
6+
sourcetype: [aws:*]
77

88
default_log_source:
9-
source_type: aws:*
9+
sourcetype: aws:*
1010

1111
field_mapping:
1212
annotations.authorization.k8s.io\/decision: annotations.authorization.k8s.io\/decision

uncoder-core/app/translator/mappings/platforms/splunk/azure_AzureDiagnostics.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_AzureDiagnostics
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
ResultDescription: ResultDescription

uncoder-core/app/translator/mappings/platforms/splunk/azure_BehaviorAnalytics.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_BehaviorAnalytics
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
ActionType: ActionType

uncoder-core/app/translator/mappings/platforms/splunk/azure_aadnoninteractiveusersigninlogs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_aadnoninteractiveusersigninlogs
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
UserAgent: UserAgent

uncoder-core/app/translator/mappings/platforms/splunk/azure_azureactivity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_azureactivity
33

44

55
log_source:
6-
source_type: [mscs:azure:*, azure:*]
6+
sourcetype: [mscs:azure:*, azure:*]
77

88
default_log_source:
9-
source_type: mscs:azure:*
9+
sourcetype: mscs:azure:*
1010

1111
field_mapping:
1212
ActivityStatus: ActivityStatus

uncoder-core/app/translator/mappings/platforms/splunk/azure_azuread.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_azuread
33

44

55
log_source:
6-
source_type: [azure:aad:*]
6+
sourcetype: [azure:aad:*]
77

88
default_log_source:
9-
source_type: azure:aad:*
9+
sourcetype: azure:aad:*
1010

1111
field_mapping:
1212
ActivityDisplayName: ActivityDisplayName

uncoder-core/app/translator/mappings/platforms/splunk/azure_signinlogs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_signinlogs
33

44

55
log_source:
6-
source_type: [azure:aad:*]
6+
sourcetype: [azure:aad:*]
77

88
default_log_source:
9-
source_type: azure:aad:*
9+
sourcetype: azure:aad:*
1010

1111
field_mapping:
1212
AppDisplayName: AppDisplayName

uncoder-core/app/translator/mappings/platforms/splunk/firewall.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,11 @@ source: firewall
33

44

55
log_source:
6-
source_type: [fortigate_traffic]
6+
sourcetype: [fortigate_traffic]
77
index: [fortigate]
88

99
default_log_source:
10-
source_type: fortigate_traffic
10+
sourcetype: fortigate_traffic
1111
index: fortigate
1212

1313
field_mapping:

uncoder-core/app/translator/mappings/platforms/splunk/gcp_gcp.audit.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ source: gcp_gcp.audit
33

44

55
log_source:
6-
source_type: [google:gcp:*]
6+
sourcetype: [google:gcp:*]
77

88
default_log_source:
99
index: google:gcp:*

0 commit comments

Comments
 (0)