|
155 | 155 | "auditd.data.a3": "keyword" |
156 | 156 | }, |
157 | 157 | "logs-aws.cloudtrail-*": { |
158 | | - "aws.cloudtrail.flattened.request_parameters.cidrIp": "keyword", |
159 | | - "aws.cloudtrail.flattened.request_parameters.fromPort": "keyword", |
160 | | - "aws.cloudtrail.flattened.request_parameters.roleArn": "keyword", |
161 | | - "aws.cloudtrail.flattened.request_parameters.roleName": "keyword", |
162 | | - "aws.cloudtrail.flattened.request_parameters.policyArn": "keyword", |
| 158 | + "aws.cloudtrail.flattened.request_parameters.ipPermissions.items.ipRanges.items.cidrIp": "keyword", |
| 159 | + "aws.cloudtrail.flattened.request_parameters.ipPermissions.items.fromPort": "keyword", |
163 | 160 | "aws.cloudtrail.flattened.request_parameters.serialNumber": "keyword", |
164 | 161 | "aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm": "keyword", |
165 | | - "aws.cloudtrail.flattened.additional_eventdata.SSEApplied": "keyword", |
166 | | - "aws.cloudtrail.flattened.request_parameters.bucketName": "keyword", |
167 | | - "aws.cloudtrail.flattened.request_parameters.key": "keyword", |
168 | 162 | "aws.cloudtrail.flattened.request_parameters.includeDeprecated": "keyword", |
169 | 163 | "aws.cloudtrail.flattened.request_parameters.withDecryption": "boolean", |
170 | 164 | "aws.cloudtrail.flattened.request_parameters.instanceId": "keyword", |
171 | | - "aws.cloudtrail.flattened.request_parameters.dryRun": "boolean", |
172 | | - "aws.cloudtrail.flattened.request_parameters.clientToken": "keyword", |
173 | | - "aws.cloudtrail.flattened.response_elements.s3BucketName": "keyword", |
174 | | - "aws.cloudtrail.flattened.response_elements.tableArn": "keyword", |
175 | 165 | "aws.cloudtrail.flattened.request_parameters.attribute": "keyword", |
176 | 166 | "aws.cloudtrail.flattened.request_parameters.reason": "keyword", |
177 | 167 | "aws.cloudtrail.flattened.request_parameters.omitted": "keyword", |
178 | | - "aws.cloudtrail.flattened.request_parameters.ownersSet.items.owner": "keyword", |
179 | | - "aws.cloudtrail.flattened.response_elements.documentDescription.documentType": "keyword" |
| 168 | + "aws.cloudtrail.flattened.response_elements.documentDescription.documentType": "keyword", |
| 169 | + "aws.cloudtrail.flattened.request_parameters.groupSet.items.groupId": "keyword" |
180 | 170 | }, |
181 | 171 | "logs-azure.signinlogs-*": { |
182 | 172 | "azure.signinlogs.properties.conditional_access_audiences.application_id": "keyword", |
|
203 | 193 | "azure.auditlogs.properties.target_resources.0.modified_properties.3.new_value": "keyword", |
204 | 194 | "azure.auditlogs.properties.target_resources.0.modified_properties.2.new_value": "keyword", |
205 | 195 | "azure.auditlogs.properties.additional_details.value": "keyword" |
| 196 | + }, |
| 197 | + "logs-azure.platformlogs-*": { |
| 198 | + "azure.platformlogs.identity.claim.upn": "keyword", |
| 199 | + "azure.platformlogs.properties.id": "keyword" |
206 | 200 | }, |
207 | 201 | "logs-o365.audit-*": { |
208 | 202 | "o365.audit.ExtendedProperties.ResultStatusDetail": "keyword", |
|
0 commit comments