Skip to content

Commit 0ad6918

Browse files
tweak
1 parent 349b2a4 commit 0ad6918

File tree

2 files changed

+27
-5
lines changed

2 files changed

+27
-5
lines changed

patterns.sed

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
s|%CommandLine%|{process.command_line}|g
1+
s|%CommandLine%|{event_data.process.command_line}|g
22
s|%community_id%|{network.community_id}|g
33
s|%CurrentDirectory%|{event_data.process.working_directory}|g
44
s|%document_id%|{soc_id}|g
55
s|%dst_port%|{destination.port}|g
66
s|%dns.query.name%|{dns.query_name}|g
77
s|%dns.resolved_ip%|{dns.resolved_ip}|g
88
s|%hostname%|{event_data.host.name}|g
9-
s|%Image%|{process.executable}|g
9+
s|%Image%|{event_data.process.executable}|g
1010
s|%ImageLoaded%|{dll.name}|g
11-
s|%ParentImage%|{process.parent.executable}|g
12-
s|%ParentProcessGuid%|{ParentProcessGuid}|g
11+
s|%ParentImage%|{event_data.process.parent.executable}|g
12+
s|%ParentProcessGuid%|{event_data.process.parent.entity_id}|g
1313
s|%private_ip%|{network.private_ip}|g
1414
s|%ProcessGuid%|{event_data.process.entity_id}|g
1515
s|%public_ip%|{network.public_ip}|g
@@ -18,5 +18,5 @@ s|%related_ip%|{related.ip}|g
1818
s|%rule.name%|{rule.name}|g
1919
s|%src_ip%|{source.ip}|g
2020
s|%dst_ip%|{destination.ip}|g
21-
s|%User%|{user.name}|g
21+
s|%User%|{event_data.user.name}|g
2222
s/|expand:/:/g

patterns.sed.bak

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
s|%CommandLine%|{process.command_line}|g
2+
s|%community_id%|{network.community_id}|g
3+
s|%CurrentDirectory%|{event_data.process.working_directory}|g
4+
s|%document_id%|{soc_id}|g
5+
s|%dst_port%|{destination.port}|g
6+
s|%dns.query.name%|{dns.query_name}|g
7+
s|%dns.resolved_ip%|{dns.resolved_ip}|g
8+
s|%hostname%|{event_data.host.name}|g
9+
s|%Image%|{process.executable}|g
10+
s|%ImageLoaded%|{dll.name}|g
11+
s|%ParentImage%|{process.parent.executable}|g
12+
s|%ParentProcessGuid%|{ParentProcessGuid}|g
13+
s|%private_ip%|{network.private_ip}|g
14+
s|%ProcessGuid%|{event_data.process.entity_id}|g
15+
s|%public_ip%|{network.public_ip}|g
16+
s|%related.hosts%|{event_data.related.hosts}|g
17+
s|%related_ip%|{related.ip}|g
18+
s|%rule.name%|{rule.name}|g
19+
s|%src_ip%|{source.ip}|g
20+
s|%dst_ip%|{destination.ip}|g
21+
s|%User%|{user.name}|g
22+
s/|expand:/:/g

0 commit comments

Comments
 (0)