Skip to content

Commit 95e0b6e

Browse files
authored
Merge pull request #161 from UncoderIO/gis-8070
Gis 8070
2 parents 5a15552 + 1b5cfdf commit 95e0b6e

30 files changed

+58
-58
lines changed

uncoder-core/app/translator/mappings/platforms/splunk/aws_cloudtrail.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: aws_cloudtrail
33

44

55
log_source:
6-
source_type: [aws:cloudtrail]
6+
sourcetype: [aws:cloudtrail]
77

88
default_log_source:
9-
source_type: aws:cloudtrail
9+
sourcetype: aws:cloudtrail
1010

1111
field_mapping:
1212
eventSource: eventSource

uncoder-core/app/translator/mappings/platforms/splunk/aws_eks.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: aws_eks
33

44

55
log_source:
6-
source_type: [aws:*]
6+
sourcetype: [aws:*]
77

88
default_log_source:
9-
source_type: aws:*
9+
sourcetype: aws:*
1010

1111
field_mapping:
1212
annotations.authorization.k8s.io\/decision: annotations.authorization.k8s.io\/decision

uncoder-core/app/translator/mappings/platforms/splunk/azure_AzureDiagnostics.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_AzureDiagnostics
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
ResultDescription: ResultDescription

uncoder-core/app/translator/mappings/platforms/splunk/azure_BehaviorAnalytics.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_BehaviorAnalytics
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
ActionType: ActionType

uncoder-core/app/translator/mappings/platforms/splunk/azure_aadnoninteractiveusersigninlogs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_aadnoninteractiveusersigninlogs
33

44

55
log_source:
6-
source_type: [azure:*]
6+
sourcetype: [azure:*]
77

88
default_log_source:
9-
source_type: azure:*
9+
sourcetype: azure:*
1010

1111
field_mapping:
1212
UserAgent: UserAgent

uncoder-core/app/translator/mappings/platforms/splunk/azure_azureactivity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_azureactivity
33

44

55
log_source:
6-
source_type: [mscs:azure:*, azure:*]
6+
sourcetype: [mscs:azure:*, azure:*]
77

88
default_log_source:
9-
source_type: mscs:azure:*
9+
sourcetype: mscs:azure:*
1010

1111
field_mapping:
1212
ActivityStatus: ActivityStatus

uncoder-core/app/translator/mappings/platforms/splunk/azure_azuread.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_azuread
33

44

55
log_source:
6-
source_type: [azure:aad:*]
6+
sourcetype: [azure:aad:*]
77

88
default_log_source:
9-
source_type: azure:aad:*
9+
sourcetype: azure:aad:*
1010

1111
field_mapping:
1212
ActivityDisplayName: ActivityDisplayName

uncoder-core/app/translator/mappings/platforms/splunk/azure_signinlogs.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: azure_signinlogs
33

44

55
log_source:
6-
source_type: [azure:aad:*]
6+
sourcetype: [azure:aad:*]
77

88
default_log_source:
9-
source_type: azure:aad:*
9+
sourcetype: azure:aad:*
1010

1111
field_mapping:
1212
AppDisplayName: AppDisplayName

uncoder-core/app/translator/mappings/platforms/splunk/firewall.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,11 @@ source: firewall
33

44

55
log_source:
6-
source_type: [fortigate_traffic]
6+
sourcetype: [fortigate_traffic]
77
index: [fortigate]
88

99
default_log_source:
10-
source_type: fortigate_traffic
10+
sourcetype: fortigate_traffic
1111
index: fortigate
1212

1313
field_mapping:

uncoder-core/app/translator/mappings/platforms/splunk/gcp_gcp.audit.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ source: gcp_gcp.audit
33

44

55
log_source:
6-
source_type: [google:gcp:*]
6+
sourcetype: [google:gcp:*]
77

88
default_log_source:
99
index: google:gcp:*

uncoder-core/app/translator/mappings/platforms/splunk/gcp_pubsub.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ source: gcp_pubsub
33

44

55
log_source:
6-
source_type: [google:gcp:*]
6+
sourcetype: [google:gcp:*]
77

88
default_log_source:
99
index: google:gcp:*

uncoder-core/app/translator/mappings/platforms/splunk/linux_auditd.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: linux_auditd
33

44

55
log_source:
6-
source_type: [linux:audit]
6+
sourcetype: [linux:audit]
77

88
default_log_source:
9-
source_type: linux:audit
9+
sourcetype: linux:audit
1010

1111
field_mapping:
1212
a0: a0

uncoder-core/app/translator/mappings/platforms/splunk/okta_okta.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: okta_okta
33

44

55
log_source:
6-
source_type: [OktaIM2:*]
6+
sourcetype: [OktaIM2:*]
77

88
default_log_source:
9-
source_type: OktaIM2:*
9+
sourcetype: OktaIM2:*
1010

1111
field_mapping:
1212
client.user.id: client.user.id

uncoder-core/app/translator/mappings/platforms/splunk/windows_bits_client.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ platform: Splunk
22
source: windows_bits_client
33

44
log_source:
5-
source_type: [XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational]
5+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational]
66

77
default_log_source:
8-
source_type: XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational
8+
sourcetype: XmlWinEventLog:Microsoft-Windows-Bits-Client/Operational
99

1010
field_mapping:
1111
LocalName: LocalName

uncoder-core/app/translator/mappings/platforms/splunk/windows_dns_query.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_dns_query
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
Image: Image

uncoder-core/app/translator/mappings/platforms/splunk/windows_driver_load.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_driver_load
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
ImageLoaded: ImageLoaded

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_access.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_access
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_change.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_change
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_create.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_create
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_delete.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_delete
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_event.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_event
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_file_rename.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_file_rename
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
CreationUtcTime: CreationUtcTime

uncoder-core/app/translator/mappings/platforms/splunk/windows_image_load.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_image_load
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
Image: Image

uncoder-core/app/translator/mappings/platforms/splunk/windows_ldap_debug.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: windows_ldap_debug
33

44

55
log_source:
6-
source_type: [XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug]
6+
sourcetype: [XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug]
77

88
default_log_source:
9-
source_type: XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug
9+
sourcetype: XmlWinEventLog:Microsoft-Windows-LDAP-Client/Debug
1010

1111
field_mapping:
1212
EventID: EventID

uncoder-core/app/translator/mappings/platforms/splunk/windows_network_connection.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_network_connection
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
Image: Image

uncoder-core/app/translator/mappings/platforms/splunk/windows_ntlm.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: windows_ntlm
33

44

55
log_source:
6-
source_type: [XmlWinEventLog:Microsoft-Windows-NTLM/Operational]
6+
sourcetype: [XmlWinEventLog:Microsoft-Windows-NTLM/Operational]
77

88
default_log_source:
9-
source_type: XmlWinEventLog:Microsoft-Windows-NTLM/Operational
9+
sourcetype: XmlWinEventLog:Microsoft-Windows-NTLM/Operational
1010

1111
field_mapping:
1212
WorkstationName: WorkstationName

uncoder-core/app/translator/mappings/platforms/splunk/windows_registry_event.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,11 @@ source: windows_registry_event
44

55
log_source:
66
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
7-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
7+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
88

99
default_log_source:
1010
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
11-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
11+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1212

1313
field_mapping:
1414
TargetObject: TargetObject

uncoder-core/app/translator/mappings/platforms/splunk/windows_sysmon.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,11 @@ source: windows_sysmon
33

44
log_source:
55
source: [WinEventLog:Microsoft-Windows-Sysmon/Operational]
6-
source_type: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
6+
sourcetype: [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
77

88
default_log_source:
99
source: WinEventLog:Microsoft-Windows-Sysmon/Operational
10-
source_type: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
sourcetype: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
1111

1212
field_mapping:
1313
CommandLine: CommandLine

uncoder-core/app/translator/mappings/platforms/splunk/windows_wmi_event.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ source: windows_wmi_event
33

44

55
log_source:
6-
source_type: [XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational]
6+
sourcetype: [XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational]
77

88
default_log_source:
9-
source_type: XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational
9+
sourcetype: XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational
1010

1111
field_mapping:
1212
Destination: Destination

uncoder-core/app/translator/platforms/splunk/mapping.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,8 @@ def prepare_log_source_signature(self, mapping: dict) -> SplunkLogSourceSignatur
4242
default_log_source = mapping["default_log_source"]
4343
return SplunkLogSourceSignature(
4444
sources=log_source.get("source"),
45-
source_types=log_source.get("source_type"),
46-
source_categories=log_source.get("source_category"),
45+
source_types=log_source.get("sourcetype"),
46+
source_categories=log_source.get("sourcecategory"),
4747
indices=log_source.get("index"),
4848
default_source=default_log_source,
4949
)

0 commit comments

Comments
 (0)