File tree Expand file tree Collapse file tree 2 files changed +23
-23
lines changed Expand file tree Collapse file tree 2 files changed +23
-23
lines changed Original file line number Diff line number Diff line change 83
83
- uid : 5579
84
84
title : Splunk Add-on for CrowdStrike FDR
85
85
appid : Splunk_TA_CrowdStrike_FDR
86
- version : 2.0.3
86
+ version : 2.0.5
87
87
description : description of app
88
- hardcoded_path : https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-crowdstrike-fdr_203 .tgz
88
+ hardcoded_path : https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-crowdstrike-fdr_205 .tgz
89
89
- uid : 3185
90
90
title : Splunk Add-on for Microsoft IIS
91
91
appid : SPLUNK_TA_FOR_IIS
Original file line number Diff line number Diff line change @@ -19,7 +19,7 @@ separator_value: ProcessRollup2
19
19
supported_TA :
20
20
- name : Splunk Add-on for CrowdStrike FDR
21
21
url : https://splunkbase.splunk.com/app/5579
22
- version : 2.0.4
22
+ version : 2.0.5
23
23
fields :
24
24
- AuthenticationId
25
25
- AuthenticationId_meaning
@@ -100,26 +100,26 @@ fields:
100
100
- user_id
101
101
- vendor_product
102
102
output_fields :
103
- - action
104
- - dest
105
- - original_file_name
106
- - parent_process
107
- - parent_process_exec
108
- - parent_process_guid
109
- - parent_process_id
110
- - parent_process_name
111
- - parent_process_path
112
- - process
113
- - process_exec
114
- - process_guid
115
- - process_hash
116
- - process_id
117
- - process_integrity_level
118
- - process_name
119
- - process_path
120
- - user
121
- - user_id
122
- - vendor_product
103
+ - action
104
+ - dest
105
+ - original_file_name
106
+ - parent_process
107
+ - parent_process_exec
108
+ - parent_process_guid
109
+ - parent_process_id
110
+ - parent_process_name
111
+ - parent_process_path
112
+ - process
113
+ - process_exec
114
+ - process_guid
115
+ - process_hash
116
+ - process_id
117
+ - process_integrity_level
118
+ - process_name
119
+ - process_path
120
+ - user
121
+ - user_id
122
+ - vendor_product
123
123
field_mappings :
124
124
- data_model : cim
125
125
data_set : Endpoint.Processes
You can’t perform that action at this time.
0 commit comments