Skip to content

Field Mappings #1981

Closed Answered by frack113
SecJesus asked this question in Q&A
Sep 2, 2021 · 2 comments · 1 reply
Discussion options

You must be logged in to vote

Hello,
the idea is to always use the original name field of the log in the sigma rule
exemple:
Windows secutity 5145 use RelativeTargetName not Account_Name or Account Name
You can see it in xml view of events viewer

Next you use sigmac option
for ELK with ECS
sigmac -t es-qs -c config\generic\sysmon.yml -c config\winlogbeat-modules-enabled.yml name_of_the_rule.yml

Then you get a query in ECS field name

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by frack113
Comment options

You must be logged in to vote
1 reply
@austinsonger
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants