This commit is contained in:
sp 2021-12-21 12:01:08 +02:00
Родитель 6e9732b1ca
Коммит 204eace7e7
2 изменённых файлов: 82 добавлений и 1 удалений

Просмотреть файл

@ -0,0 +1,81 @@
{
"name": "VMwareESXi",
"Properties": [
{
"Name": "TenantId",
"Type": "String"
},
{
"Name": "SourceSystem",
"Type": "String"
},
{
"Name": "TimeGenerated",
"Type": "DateTime"
},
{
"Name": "Computer",
"Type": "String"
},
{
"Name": "EventTime",
"Type": "DateTime"
},
{
"Name": "Facility",
"Type": "String"
},
{
"Name": "HostName",
"Type": "String"
},
{
"Name": "SeverityLevel",
"Type": "String"
},
{
"Name": "SyslogMessage",
"Type": "String"
},
{
"Name": "ProcessID",
"Type": "Int"
},
{
"Name": "HostIP",
"Type": "String"
},
{
"Name": "ProcessName",
"Type": "String"
},
{
"Name": "MG",
"Type": "String"
},
{
"Name": "Type",
"Type": "String"
},
{
"Name": "_ResourceId",
"Type": "String"
},
{
"Name": "Sub",
"Type": "String"
},
{
"Name": "OpId",
"Type": "String"
},
{
"Name": "UserName",
"Type": "String"
},
{
"Name": "Message",
"Type": "String"
}
]
}

Просмотреть файл

@ -21,7 +21,7 @@ query: |
| extend user = 'root'
| extend AccountCustomEntity = user
entityMappings:
- entityType: Accounr
- entityType: Account
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity