Skip to content

Commit 0bf1bac

Browse files
committed
updating example
1 parent 56f8742 commit 0bf1bac

File tree

2 files changed

+122
-0
lines changed

2 files changed

+122
-0
lines changed

data_sources/aws_cloudtrail_describesnapshotattribute.yml

Lines changed: 121 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,5 +12,126 @@ supported_TA:
1212
url: https://splunkbase.splunk.com/app/1876
1313
version: 7.9.0
1414
fields:
15+
- action
16+
- app
17+
- authentication_method
18+
- awsRegion
19+
- aws_account_id
20+
- change_type
21+
- command
22+
- date_hour
23+
- date_mday
24+
- date_minute
25+
- date_month
26+
- date_second
27+
- date_wday
28+
- date_year
29+
- date_zone
30+
- desc
31+
- dest
32+
- dest_ip_range
33+
- dest_port_range
34+
- direction
35+
- dvc
36+
- errorCode
37+
- errorMessage
38+
- eventCategory
39+
- eventID
40+
- eventName
41+
- eventSource
42+
- eventTime
43+
- eventType
44+
- eventVersion
45+
- eventtype
46+
- host
47+
- image_id
48+
- index
49+
- instance_type
50+
- linecount
51+
- managementEvent
52+
- msg
53+
- object
54+
- object_attrs
55+
- object_category
56+
- object_id
57+
- product
58+
- protocol
59+
- protocol_code
60+
- punct
61+
- readOnly
62+
- reason
63+
- recipientAccountId
64+
- region
65+
- requestID
66+
- requestParameters.attributeType
67+
- requestParameters.snapshotId
68+
- responseElements
69+
- result
70+
- result_id
71+
- rule_action
72+
- signature
73+
- source
74+
- sourceIPAddress
75+
- sourcetype
76+
- splunk_server
77+
- splunk_server_group
78+
- src
79+
- src_ip
80+
- src_ip_range
81+
- src_port_range
82+
- src_user
83+
- src_user_id
84+
- src_user_name
85+
- src_user_role
86+
- src_user_type
87+
- start_time
88+
- status
89+
- tag
90+
- tag::action
91+
- tag::app
92+
- tag::eventtype
93+
- tag::object_category
94+
- temp_access_key
95+
- timeendpos
96+
- timestartpos
97+
- tlsDetails.cipherSuite
98+
- tlsDetails.clientProvidedHostHeader
99+
- tlsDetails.tlsVersion
100+
- user
101+
- userAgent
102+
- userIdentity.accessKeyId
103+
- userIdentity.accountId
104+
- userIdentity.arn
105+
- userIdentity.principalId
106+
- userIdentity.sessionContext.attributes.creationDate
107+
- userIdentity.sessionContext.attributes.mfaAuthenticated
108+
- userIdentity.sessionContext.sessionIssuer.accountId
109+
- userIdentity.sessionContext.sessionIssuer.arn
110+
- userIdentity.sessionContext.sessionIssuer.principalId
111+
- userIdentity.sessionContext.sessionIssuer.type
112+
- userIdentity.sessionContext.sessionIssuer.userName
113+
- userIdentity.type
114+
- userName
115+
- user_access_key
116+
- user_agent
117+
- user_arn
118+
- user_group_id
119+
- user_id
120+
- user_name
121+
- user_role
122+
- user_type
123+
- vendor
124+
- vendor_account
125+
- vendor_product
126+
- vendor_region
127+
- _bkt
128+
- _cd
129+
- _eventtype_color
130+
- _indextime
131+
- _raw
132+
- _serial
133+
- _si
134+
- _sourcetype
15135
- _time
16136
example_log: |-
137+
{"eventVersion": "1.10", "userIdentity": {"type": "AssumedRole", "principalId": "AROAYTOGP2RLBXYPYUKBH:aws-go-sdk-1740131590946446551", "arn": "arn:aws:sts::111111111111111:assumed-role/DAFTPUNK-cloud-security-audit/aws-go-sdk-1740131590946446551", "accountId": "111111111111111", "accessKeyId": "DAFTPUNK", "sessionContext": {"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLBXYPYUKBH", "arn": "arn:aws:iam::111111111111111:role/DAFTPUNK-cloud-security-audit", "accountId": "111111111111111", "userName": "DAFTPUNK-cloud-security-audit"}, "attributes": {"creationDate": "2025-02-21T10:48:43Z", "mfaAuthenticated": "false"}}}, "eventTime": "2025-02-21T11:29:27Z", "eventSource": "ec2.amazonaws.com", "eventName": "DescribeSnapshotAttribute", "awsRegion": "eu-central-1", "sourceIPAddress": "54.203.114.197", "userAgent": "m/E aws-sdk-go-v2/1.30.5 os/linux lang/go#1.22.4 md/GOOS#linux md/GOARCH#amd64 api/ec2#1.177.3", "requestParameters": {"snapshotId": "snap-082bd5016636bbd94", "attributeType": "PRODUCT_CODES"}, "responseElements": null, "requestID": "70339070-6038-40b7-9acf-5ecb85cda843", "eventID": "bcc65c3f-a997-4a01-90bf-3b85f7268e70", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.eu-central-1.amazonaws.com"}}

data_sources/azure_active_directory_microsoftgraphactivitylogs.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,3 +14,4 @@ supported_TA:
1414
fields:
1515
- _time
1616
example_log: |-
17+
{"time": "2024-04-30T01:22:46.4948958Z", "resourceId": "/TENANTS/225E05A1-5914-4688-A404-7030E60F3143/PROVIDERS/MICROSOFT.AADIAM", "operationName": "Microsoft Graph Activity", "operationVersion": "beta", "category": "MicrosoftGraphActivityLogs", "resultSignature": "200", "durationMs": "948894", "callerIpAddress": "45.83.145.6", "correlationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "level": "Informational", "location": "East US 2", "properties": {"__UDI_RequiredFields_TenantId": "225e05a1-5914-4688-a404-7030e60f3143", "__UDI_RequiredFields_UniqueId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "__UDI_RequiredFields_EventTime": 638500369660000000, "__UDI_RequiredFields_RegionScope": "NA", "timeGenerated": "2024-04-30T01:22:46.4948958Z", "location": "East US 2", "requestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "operationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "clientRequestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "apiVersion": "beta", "requestMethod": "GET", "responseStatusCode": 200, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143", "durationMs": 948894, "responseSizeBytes": 91, "signInActivityId": "KRsphQ_4s0-oHv_Br8qSAQ", "roles": "", "appId": "1950a258-227b-4e31-a9cf-717495945fc2", "UserPrincipalObjectID": "7b934539-7366-494e-a8ac-3517694d32db", "scopes": "AuditLog.Read.All Directory.AccessAsUser.All email openid profile", "identityProvider": "", "clientAuthMethod": "0", "wids": "b79fbf4d-3ef9-4689-8143-76b194e85509", "C_Idtyp": "user", "C_Iat": "1714439850", "ipAddress": "45.83.145.6", "userAgent": "azurehound/v2.1.8", "requestUri": "https://graph.microsoft.com/beta/servicePrincipals/ffe3e001-d8cf-43a4-89ab-bfce35fd7786/owners?%24top=999", "userId": "7b934539-7366-494e-a8ac-3517694d32db", "tokenIssuedAt": "2024-04-30T01:17:30.0000000Z"}, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143"}

0 commit comments

Comments
 (0)