Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <decoder name="sentinelone">
- <prematch>CEF:\d+\|SentinelOne\|</prematch>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventID=(\d+)</regex>
- <order>sentinelone.eventID</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventDesc=(\.+)\|</regex>
- <order>sentinelone.eventDesc</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|eventSeverity=(\d+)\|</regex>
- <order>sentinelone.eventSeverity</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceIpAddresses=(\.+)\|</regex>
- <order>sentinelone.sourceIpAddresses</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|fileHash=(\.+)\|</regex>
- <order>sentinelone.fileHash</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|filePath=(\.+)\|</regex>
- <order>sentinelone.filePath</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|fileName=(\.+)\|</regex>
- <order>sentinelone.fileName</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|originatorName=(\.+)\|</regex>
- <order>sentinelone.originatorName</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceOsType=(\.+)\|</regex>
- <order>sentinelone.sourceOsType</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceOsRevision=(\.+)\|</regex>
- <order>sentinelone.sourceOsRevision</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceThreatCount=(\d+)\|</regex>
- <order>sentinelone.sourceThreatCount</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceHostName=(\.+)\|</regex>
- <order>sentinelone.sourceHostName</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|sourceGroupName=(\.+)\|</regex>
- <order>sentinelone.sourceGroupName</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatClassification=(\.+)\|</regex>
- <order>sentinelone.threatClassification</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatClassificationSource=(\.+)\|</regex>
- <order>sentinelone.threatClassificationSource</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatDetectingEngine=(\.+)\|</regex>
- <order>sentinelone.threatDetectingEngine</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatMitigationStatus=(\.+)\|</regex>
- <order>sentinelone.threatMitigationStatus</order>
- </decoder>
- <decoder name="sentinelone-fields">
- <parent>sentinelone</parent>
- <regex>\|SentinelOne\|\w+\|\S+\|\S+\|\.+\|threatConfidenceLevel=(\.+)\|</regex>
- <order>sentinelone.threatConfidenceLevel</order>
- </decoder>
Advertisement
Add Comment
Please, Sign In to add comment