-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Description
Historically under LEA the following;
sourcetype=opsec product="connectra"
Where not CIM compatible, we have noted many missing fields, the most important are those required to complete the Authentication datamodel. https://docs.splunk.com/Documentation/CIM/4.12.0/User/Authentication
These can be seen when running the following index=* (sourcetype=opsec product="connectra") | table action app dest duration signature signature_id src user (under LEA)
The following fields are required at a minimum
action
app
dest
duration
signature
src
user
Metadata
Metadata
Assignees
Labels
No labels