Skip to content
This repository was archived by the owner on Dec 30, 2023. It is now read-only.

Conversation

@edoardovicendone
Copy link

In the "windefender_signature_lookup" the "signature" field should output as a "signature_id_description" to avoid overwriting the "signature" field that is recommended for the Malware DataModel:

https://docs.splunk.com/Documentation/CIM/5.2.0/User/Malware

"The name of the malware infection detected on the client (the dest)."

In the "windefender_signature_lookup" the "signature" field should output as a "signature_id_description" to avoid overwriting the "signature" field that is recommended for the Malware DataModel:

https://docs.splunk.com/Documentation/CIM/5.2.0/User/Malware

"The name of the malware infection detected on the client (the dest)."
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant