Skip to content

Commit

Permalink
UPDATED
Browse files Browse the repository at this point in the history
  • Loading branch information
Alekhya0824 committed Dec 11, 2024
1 parent ca38598 commit d4953c3
Show file tree
Hide file tree
Showing 3 changed files with 18 additions and 15 deletions.
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Parser:
Title: Authentication ASIM filtering parser for Windows Security Events
Version: '0.3.1'
LastUpdated: Dece 11, 2024
LastUpdated: Oct 15, 2024
Product:
Name: Windows Security Events
Normalization:
Expand Down
29 changes: 16 additions & 13 deletions Parsers/ASimAuthentication/Parsers/vimAuthenticationNative.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,24 +23,27 @@ ParserParams:
- Name: endtime
Type: datetime
Default: datetime(null)
- Name: srcipaddr
Type: string
Default: '*'
- Name: domain_has_any
- Name: username_has_any
Type: dynamic
Default: dynamic([])
- Name: responsecodename
Type: string
Default: '*'
- Name: response_has_ipv4
Type: string
Default: '*'
- Name: response_has_any_prefix
- Name: targetappname_has_any
Type: dynamic
Default: dynamic([])
- Name: srcipaddr_has_any_prefix
Type: dynamic
Default: dynamic([])
- Name: eventtype
- Name: srchostname_has_any
Type: dynamic
Default: dynamic([])
- Name: eventtype_in
Type: dynamic
Default: dynamic([])
- Name: eventresultdetails_in
Type: dynamic
Default: dynamic([])
- Name: eventresult
Type: string
Default: 'Query'
Default: '*'
- Name: disabled
Type: bool
Default: false
Expand Down
2 changes: 1 addition & 1 deletion Parsers/ASimDns/Parsers/ASimDnsNative.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Parser:
Title: DNS activity ASIM parser for Microsoft Sentinel native DNS table
Version: '0.6.1'
LastUpdated: Dece 01 2023
LastUpdated: March 01 2023
Product:
Name: Native
Normalization:
Expand Down

0 comments on commit d4953c3

Please sign in to comment.