Skip to content

Commit f88057e

Browse files
committed
Merge branch 'release/v11' of https://github.com/utmstack/UTMStack into release/v11
2 parents d191ce9 + 0755290 commit f88057e

11 files changed

Lines changed: 1664 additions & 2079 deletions

File tree

filters/aws/aws.yml

Lines changed: 1308 additions & 4 deletions
Large diffs are not rendered by default.

filters/office365/o365-all.conf

Lines changed: 0 additions & 17 deletions
This file was deleted.

filters/office365/o365.yml

Lines changed: 85 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,85 @@
1+
# Microsoft 365 filter
2+
# Based on Official documentation
3+
# See https://learn.microsoft.com/en-us/compliance/assurance/assurance-microsoft-365-audit-log-collection
4+
# https://learn.microsoft.com/es-es/office/office-365-management-api/aip-unified-audit-logs-best-practices
5+
# https://learn.microsoft.com/en-us/purview/audit-log-activities
6+
pipeline:
7+
- dataTypes:
8+
- o365
9+
steps:
10+
- json:
11+
source: raw
12+
13+
- rename:
14+
from:
15+
- log.AppAccessContext.AADSessionId
16+
to: log.appAccessContextAADSessionId
17+
18+
- rename:
19+
from:
20+
- log.AppAccessContext.APIId
21+
to: log.appAccessContextAPIId
22+
23+
- rename:
24+
from:
25+
- log.AppAccessContext.ClientAppId
26+
to: log.appAccessContextClientAppId
27+
28+
- rename:
29+
from:
30+
- log.AppAccessContext.CorrelationId
31+
to: log.appAccessContextCorrelationId
32+
33+
- rename:
34+
from:
35+
- log.AppAccessContext.IssuedAtTime
36+
to: log.deviceTime
37+
38+
- rename:
39+
from:
40+
- log.AppAccessContext.UniqueTokenId
41+
to: log.appAccessContextUniqueTokenId
42+
43+
- rename:
44+
from:
45+
- log.ClientIPAddress
46+
to: origin.ip
47+
48+
- rename:
49+
from:
50+
- log.Operation
51+
to: action
52+
53+
- rename:
54+
from:
55+
- log.Version
56+
to: log.version
57+
58+
- rename:
59+
from:
60+
- log.ClientIP
61+
to: log.clientIP
62+
63+
- rename:
64+
from:
65+
- log.ResultStatus
66+
to: actionResult
67+
68+
- rename:
69+
from:
70+
- log.UserId
71+
to: origin.user
72+
73+
# Drop unnecessary events
74+
- drop:
75+
where:
76+
variables:
77+
- get: action
78+
as: action
79+
oftype: string
80+
expression: action=="SupervisionRuleMatch" || action=="SupervisoryReviewTag" || action=="ComplianceManagerAutomationChange" || action=="LabelContentExplorerAccessedItem" || action=="CreateCopilotPlugin" || action=="CreateCopilotPromptBook" || action=="DeleteCopilotPlugin" || action=="DeleteCopilotPromptBook" || action=="DisableCopilotPlugin" || action=="DisableCopilotPromptBook" || action=="EnableCopilotPlugin" || action=="EnableCopilotPromptBook" || action=="CopilotInteraction" || action=="UpdateCopilotPlugin" || action=="UpdateCopilotPromptBook" || action=="UpdateCopilotSettings" || action=="ApproveDisposal" || action=="ExtendRetention" || action=="RelabelItem" || action=="SearchUpdated" || action=="CaseUpdated" || action=="SearchPermissionUpdated" || action=="HoldUpdated" || action=="PreviewItemDownloaded" || action=="PreviewItemListed" || action=="SearchCreated" || action=="CaseAdded" || action=="HoldCreated" || action=="SearchRemoved" || action=="HoldRemoved" || action=="SearchExportDownloaded" || action=="SearchPreviewed" || action=="SearchResultsPurged" || action=="RemovedSearchResultsSentToZoom" || action=="RemovedSearchExported" || action=="RemovedSearchPreviewed" || action=="RemovedSearchResultsPurged" || action=="SearchReportRemoved" || action=="SearchResultsSentToZoom" || action=="SearchStarted" || action=="SearchExported" || action=="SearchReport" || action=="SearchStopped" || action=="SearchViewed" || action=="ViewedSearchExported" || action=="ViewedSearchPreviewed" || action=="AddRemediatedData" || action=="BurnJob" || action=="CreateWorkingSet" || action=="CreateWorkingSetSearch" || action=="CreateTag" || action=="DeleteWorkingSetSearch" || action=="DeleteTag" || action=="DownloadDocument" || action=="UpdateTag" || action=="ExportJob" || action=="UpdateWorkingSetSearch" || action=="PreviewWorkingSetSearch" || action=="ErrorRemediationJob" || action=="TagFiles" || action=="TagJob" || action=="ViewDocument" || action=="Copy" || action=="Create" || action=="ApplyRecordLabel" || action=="HardDelete" || action=="Send" || action=="Update" || action=="FileAccessed" || action=="FileAccessedExtended" || action=="ComplianceSettingChanged" || action=="LockRecord" || action=="UnlockRecord" || action=="FileCheckedIn" || action=="FileCheckedOut" || action=="FileCopied" || action=="FileDeletedFirstStageRecycleBin" || action=="FileDeletedSecondStageRecycleBin" || action=="RecordDelete" || action=="DocumentSensitivityMismatchDetected" || action=="FileCheckOutDiscarded" || action=="FileDownloaded" || action=="FileModifiedExtended" || action=="FilePreviewed" || action=="SearchQueryPerformed" || action=="FileRecycled" || action=="FolderRecycled" || action=="FileVersionsAllMinorsRecycled" || action=="FileVersionsAllRecycled" || action=="FileVersionRecycled" || action=="FileRestored" || action=="FileUploaded" || action=="PageViewed" || action=="PageViewedExtended" || action=="ClientViewSignaled" || action=="PagePrefetched" || action=="FolderCopied" || action=="FolderCreated" || action=="FolderDeletedFirstStageRecycleBin" || action=="FolderDeletedSecondStageRecycleBin" || action=="FolderRestored" || action=="InformationBarriersInsightsReportCompleted" || action=="InformationBarriersInsightsReportOneDriveSectionQueried" || action=="InformationBarriersInsightsReportSchedule" || action=="InformationBarriersInsightsReportSharePointSectionQueried" || action=="updateddeviceconfiguration" || action=="UpdatedPolicyConfigPriority" || action=="BackupPolicyActivated" || action=="RestoreTaskActivated" || action=="BackupItemAdded" || action=="BackupItemRemoved" || action=="RestoreTaskCompleted" || action=="DraftRestoreTaskCreated" || action=="NewBackupPolicyCreated" || action=="DraftRestoreTaskDeleted" || action=="DraftRestoreTaskEdited" || action=="BackupPolicyPaused" || action=="GetBackupItem" || action=="ViewBackupPolicyDetails" || action=="GetRestoreTaskDetails" || action=="ListAllBackupPolicies" || action=="ListAllBackupItemsInPolicies" || action=="ListAllBackupItemsInTenant" || action=="ListAllBackupItemsInWorkload" || action=="GetAllRestoreArtifactsInTask" || action=="ListAllRestorePoints" || action=="ListAllRestoreTasks" || action=="BackupItemRestoreCompleted" || action=="BackupItemRestoreTriggered" || action=="SetAdvancedFeatures" || action=="RunAntiVirusScan" || action=="LogsCollection" || action=="TaggingConfigurationUpdated" || action=="AlertExcelDownloaded" || action=="RemediationActionAdded" || action=="RemediationActionUpdated" || action=="SensorCreated" || action=="SensorDeploymentAccessKeyReceived" || action=="SensorDeploymentAccessKeyUpdated" || action=="SensorActivationMethodConfigurationUpdated" || action=="DomainControllerCoverageExcelDownloaded" || action=="MonitoringAlertUpdated" || action=="ReportDownloaded" || action=="AlertNotificationsRecipientAdded" || action=="MonitoringAlertNotificationRecipientAdded" || action=="WorkspaceCreated" || action=="AddCommentToIncident." || action=="AssignUserToIncident" || action=="UpdateIncidentStatus" || action=="AddTagsToIncident" || action=="RemoveTagsFromIncident" || action=="CreateComment" || action=="CreateForm" || action=="MoveForm" || action=="ViewForm" || action=="PreviewForm" || action=="ExportForm" || action=="AllowShareFormForCopy" || action=="DisallowShareFormForCopy" || action=="AddFormCoauthor" || action=="RemoveFormCoauthor" || action=="ViewRuntimeForm" || action=="CreateResponse" || action=="UpdateResponse" || action=="ViewResponses" || action=="ViewResponse" || action=="GetSummaryLink" || action=="DeleteSummaryLink" || action=="ProInvitation" || action=="ListForms" || action=="SubmitResponse" || action=="ConnectToExcelWorkbook" || action=="CollectionCreated" || action=="CollectionUpdated" || action=="CollectionHardDeleted" || action=="CollectionSoftDeleted" || action=="CollectionRenamed" || action=="MovedFormIntoCollection" || action=="MovedFormOutofCollection" || action=="PlanCopied" || action=="TaskAssigned" || action=="TaskCompleted" || action=="PlanListRead" || action=="TaskListRead" || action=="ProjectCreated" || action=="RoadmapCreated" || action=="RoadmapItemCreated" || action=="TaskCreated" || action=="ProjectListAccessed" || action=="RoadmapAccessed" || action=="RoadmapItemAccessed" || action=="TaskAccessed" || action=="AuditSearchCreated" || action=="AuditSearchCompleted" || action=="AuditSearchCancelled" || action=="AuditSearchExportJobCreated" || action=="AuditSearchExportJobCompleted" || action=="AuditSearchExportResultsDownloaded" || action=="EntityCreated" || action=="ClassificationAdded" || action=="ClassificationDefinitionCreated" || action=="GlossaryTermAssigned" || action=="GlossaryTermCreated" || action=="BotAddedToTeam" || action=="ChannelAdded" || action=="ConnectorAdded" || action=="MeetingDetail" || action=="MeetingParticipantDetail" || action=="MemberAdded" || action=="TabAdded" || action=="SensitivityLabelApplied" || action=="SensitivityLabelChanged" || action=="ChatCreated" || action=="TeamCreated" || action=="MessageDeleted" || action=="MessageEditedHasLink" || action=="MessagesExported" || action=="RecordingExported" || action=="TranscriptsExported" || action=="FailedValidation" || action=="ChatRetrieved" || action=="MessageHostedContentsListed" || action=="PerformedCardAction" || action=="MessageSent" || action=="AINotesUpdate" || action=="LiveNotesUpdate" || action=="AppPublishedToCatalog" || action=="MessageRead" || action=="InviteeResponded" || action=="ChannelOwnerResponded" || action=="MessagesListed" || action=="MessageCreatedHasLink" || action=="MessageCreatedNotification" || action=="MessageDeletedNotification" || action=="MessageUpdatedNotification" || action=="InviteSent" || action=="SubscribedToMessages" || action=="AppUpdatedInCatalog" || action=="ChatUpdated" || action=="MessageUpdated" || action=="TabUpdated" || action=="AppUpgraded" || action=="MessageSent" || action=="ScheduleGroupAdded" || action=="ShiftAdded" || action=="TimeOffAdded" || action=="OpenShiftAdded" || action=="ScheduleShared" || action=="ClockedIn" || action=="ClockedOut" || action=="BreakEnded" || action=="TimeClockEntryAdded" || action=="RequestAdded" || action=="RequestRespondedTo" || action=="WorkforceIntegrationAdded" || action=="OffShiftDialogAccepted" || action=="CreateUpdateRequest" || action=="EditUpdateRequest" || action=="SubmitUpdate" || action=="ViewUpdate" || action=="AcceptedSharingLinkOnFolder" || action=="FolderSharingLinkShared" || action=="LinkedEntityCreated" || action=="SubTaskCreated" || action=="TaskCreated" || action=="TaskRead" || action=="TaskListCreated" || action=="TaskListRead" || action=="AccessedOdataLink" || action=="CanceledQuery" || action=="DeletedResult" || action=="DownloadedReport" || action=="ExecutedQuery" || action=="UploadedOrgData" || action=="ViewedExplore" || action=="QuarantineReleaseRequestDeny" || action=="QuarantinePreview" || action=="QuarantineReleaseRequest" || action=="QuarantineViewHeader" || action=="UpdateUsageReportsPrivacySetting" || action=="NewAdaptiveScope" || action=="NewComplianceTag" || action=="NewRetentionCompliancePolicy" || action=="RemoveAdaptiveScope" || action=="RemoveComplianceTag" || action=="SetRestrictiveRetentionUI" || action=="ExchangeDataProactivelyPreserved" || action=="SharePointDataProactivelyPreserved" || action=="ListCreated" || action=="ListColumnCreated" || action=="ListContentTypeCreated" || action=="ListItemCreated" || action=="SiteColumnCreated" || action=="SiteContentTypeCreated" || action=="ListContentTypeDeleted" || action=="SiteColumnDeleted" || action=="SiteContentTypeDeleted" || action=="ListItemRecycled" || action=="ListItemRestored" || action=="ListColumnUpdated" || action=="ListContentTypeUpdated" || action=="SiteColumnUpdated" || action=="SiteContentTypeUpdated" || action=="SharingInvitationCreated" || action=="AccessRequestUpdated" || action=="SharingInvitationUpdated" || action=="SharingInvitationRevoked" || action=="AllowedDataLocationAdded" || action=="SiteGeoMoveCancelled" || action=="MigrationJobCompleted" || action=="SiteGeoMoveCompleted" || action=="SiteCollectionCreated" || action=="HubSiteOrphanHubDeleted" || action=="PreviewModeEnabledSet" || action=="LegacyWorkflowEnabledSet" || action=="OfficeOnDemandSet" || action=="PeopleResultsScopeSet" || action=="NewsFeedEnabledSet" || action=="HubSiteJoined" || action=="SiteCollectionQuotaModified" || action=="HubSiteRegistered" || action=="SiteGeoMoveScheduled" || action=="GeoQuotaAllocated" || action=="SiteAdminChangeRequest" || action=="ManagedSyncClientAllowed" || action=="FileSyncDownloadedFull" || action=="FileSyncUploadedFull" || action=="DataShareCreated" || action=="DataShareDeleted" || action=="GenerateCopyOfLakeData" || action=="DownloadCopyOfLakeData" || action=="SoftDeleteSettingsUpdated" || action=="CloseConversation" || action=="OpenConversation" || action=="MessageCreation" || action=="MessageDeleted" || action=="FileDownloaded" || action=="DataExport" || action=="ThreadAccessFailure" || action=="MarkedMessageChanged" || action=="RemoveCuratedTopic" || action=="UsagePolicyAcceptance" || action=="AdminThreadMuted" || action=="AdminThreadUnmuted" || action=="FileUpdateDescription" || action=="MessageUpdated" || action=="FileVisited" || action=="ThreadViewed" || action=="PulseSubmit" || action=="PulseCreate" || action=="PulseExtendDeadline" || action=="PulseInvite" || action=="PulseCancel" || action=="PulseShareResults" || action=="PulseCreateDraft" || action=="PulseDeleteDraft"
81+
82+
# Removing unused fields
83+
- delete:
84+
fields:
85+
- log.AppAccessContext

filters/sophos/sophos_central.yml

Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
# Sophos_Central filter using "SF syslog file guide 20.0", version 1.0.0
2+
3+
# See: https://docs.sophos.com/nsg/sophos-firewall/20.0/pdf/sf-syslog-guide-20.0.pdf
4+
# and https://docs.sophos.com/nsg/sophos-firewall/20.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Logs/TroubleshootingLogs/LogFileDetails/index.html#https-ftp-waf
5+
6+
pipeline:
7+
- dataTypes:
8+
- sophos-central
9+
steps:
10+
- json:
11+
source: raw
12+
13+
- rename:
14+
from:
15+
- log.coreremedyitems
16+
to: log.coreremedyItems
17+
18+
- rename:
19+
from:
20+
- log.createdat
21+
to: log.createdAt
22+
23+
- rename:
24+
from:
25+
- log.customerid
26+
to: log.customerId
27+
28+
- rename:
29+
from:
30+
- log.endpointid
31+
to: log.endpointId
32+
33+
- rename:
34+
from:
35+
- log.endpointtype
36+
to: log.endpointType
37+
38+
- rename:
39+
from:
40+
- log.sourceinfo.ip
41+
to: log.ip
42+
43+
- rename:
44+
from:
45+
- log.userid
46+
to: log.userId
47+
48+
- rename:
49+
from:
50+
- log.sourceinfo
51+
to: log.sourceInfo

0 commit comments

Comments
 (0)