System Event Schema #83
randomuserid
started this conversation in
General
Replies: 1 comment 1 reply
-
Process events can be normalized like this in alignment with [Sigma] (https://github.com/SigmaHQ/sigma-specification/blob/main/appendix/sigma-taxonomy-appendix.md#category-folder) and Sysmon
network events like this:
and user events like this:
category values can be populated with these values for alignment: process_existing The user component creates two event types, existing user and new user detected. I think these can remain as they are because there is no direct analogue Sysmon event to align them with. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
This is the existing field schema for the streaming events:
Process Logs
Network Logs
User Detection Logs
Beta Was this translation helpful? Give feedback.
All reactions