Guest User

Untitled

a guest
Jun 6th, 2025
13
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.77 KB | None | 0 0
  1. <decoder name="sentinelone">
  2. <prematch>CEF:\d+\|SentinelOne\|</prematch>
  3. </decoder>
  4.  
  5. <decoder name="sentinelone-fields">
  6. <parent>sentinelone</parent>
  7. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventID=(\d+)</regex>
  8. <order>sentinelone.eventID</order>
  9. </decoder>
  10. <decoder name="sentinelone-fields">
  11. <parent>sentinelone</parent>
  12. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventDesc=(\.+)\|</regex>
  13. <order>sentinelone.eventDesc</order>
  14. </decoder>
  15. <decoder name="sentinelone-fields">
  16. <parent>sentinelone</parent>
  17. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventSeverity=(\d+)\|</regex>
  18. <order>sentinelone.eventSeverity</order>
  19. </decoder>
  20. <decoder name="sentinelone-fields">
  21. <parent>sentinelone</parent>
  22. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceIpAddresses=(\.+)\|</regex>
  23. <order>sentinelone.sourceIpAddresses</order>
  24. </decoder>
  25. <decoder name="sentinelone-fields">
  26. <parent>sentinelone</parent>
  27. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|fileHash=(\.+)\|</regex>
  28. <order>sentinelone.fileHash</order>
  29. </decoder>
  30. <decoder name="sentinelone-fields">
  31. <parent>sentinelone</parent>
  32. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|filePath=(\.+)\|</regex>
  33. <order>sentinelone.filePath</order>
  34. </decoder>
  35. <decoder name="sentinelone-fields">
  36. <parent>sentinelone</parent>
  37. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|fileName=(\.+)\|</regex>
  38. <order>sentinelone.fileName</order>
  39. </decoder>
  40. <decoder name="sentinelone-fields">
  41. <parent>sentinelone</parent>
  42. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|originatorName=(\.+)\|</regex>
  43. <order>sentinelone.originatorName</order>
  44. </decoder>
  45. <decoder name="sentinelone-fields">
  46. <parent>sentinelone</parent>
  47. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceOsType=(\.+)\|</regex>
  48. <order>sentinelone.sourceOsType</order>
  49. </decoder>
  50. <decoder name="sentinelone-fields">
  51. <parent>sentinelone</parent>
  52. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceOsRevision=(\.+)\|</regex>
  53. <order>sentinelone.sourceOsRevision</order>
  54. </decoder>
  55. <decoder name="sentinelone-fields">
  56. <parent>sentinelone</parent>
  57. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceThreatCount=(\d+)\|</regex>
  58. <order>sentinelone.sourceThreatCount</order>
  59. </decoder>
  60. <decoder name="sentinelone-fields">
  61. <parent>sentinelone</parent>
  62. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceHostName=(\.+)\|</regex>
  63. <order>sentinelone.sourceHostName</order>
  64. </decoder>
  65. <decoder name="sentinelone-fields">
  66. <parent>sentinelone</parent>
  67. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceGroupName=(\.+)\|</regex>
  68. <order>sentinelone.sourceGroupName</order>
  69. </decoder>
  70. <decoder name="sentinelone-fields">
  71. <parent>sentinelone</parent>
  72. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatClassification=(\.+)\|</regex>
  73. <order>sentinelone.threatClassification</order>
  74. </decoder>
  75. <decoder name="sentinelone-fields">
  76. <parent>sentinelone</parent>
  77. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatClassificationSource=(\.+)\|</regex>
  78. <order>sentinelone.threatClassificationSource</order>
  79. </decoder>
  80. <decoder name="sentinelone-fields">
  81. <parent>sentinelone</parent>
  82. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatDetectingEngine=(\.+)\|</regex>
  83. <order>sentinelone.threatDetectingEngine</order>
  84. </decoder>
  85. <decoder name="sentinelone-fields">
  86. <parent>sentinelone</parent>
  87. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatMitigationStatus=(\.+)\|</regex>
  88. <order>sentinelone.threatMitigationStatus</order>
  89. </decoder>
  90. <decoder name="sentinelone-fields">
  91. <parent>sentinelone</parent>
  92. <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatConfidenceLevel=(\.+)\|</regex>
  93. <order>sentinelone.threatConfidenceLevel</order>
  94. </decoder>
Advertisement
Add Comment
Please, Sign In to add comment