Activity Feed
- Karma Re: sysmon fields mapping to endpoint datamodel for richgalloway. 01-17-2024 10:25 PM
- Posted sysmon fields mapping to endpoint datamodel on Splunk Enterprise Security. 01-16-2024 11:33 PM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
01-16-2024
11:33 PM
I'm trying to look for refernce or documintation that shows me which fields in sysmon logs should be mapped to which fields in endpoint datamodel. for example Image & ParentImage it should show in which fields from endpoint datamodel since we have multiple fields for processes and parent processes it is confusing.
... View more
Labels
- Labels:
-
troubleshooting