yaml structure bug
This commit is contained in:
Родитель
e59ad5407d
Коммит
d79c1596bf
|
@ -12,7 +12,7 @@ References:
|
|||
Link: https://aka.ms/AzSentinelDnsDoc
|
||||
- Title: ASIM
|
||||
Link: https:/aka.ms/AzSentinelNormalization
|
||||
Description: ASIM Sysmon DNS Parametrized Parser (event number 22) from "Event" and "WindowsEvent" tables.
|
||||
Description: ASIM Sysmon DNS Parametrized Parser (event number 22) from "Event" and "WindowsEvent" tables.
|
||||
ParserName: vimDnsMicrosoftSysmon
|
||||
ParserParams:
|
||||
- Name: starttime
|
||||
|
@ -183,4 +183,4 @@ ParserQuery: |
|
|||
Query=DnsQuery,
|
||||
ResponseCodeName=DnsResponseCodeName
|
||||
};
|
||||
ParsedDnsEvent (starttime, endtime, srcipaddr, domain_has_any, responsecodename, response_has_ipv4, response_has_any_prefix, eventtype)
|
||||
ParsedDnsEvent (starttime, endtime, srcipaddr, domain_has_any, responsecodename, response_has_ipv4, response_has_any_prefix, eventtype)
|
||||
|
|
Загрузка…
Ссылка в новой задаче