Files
DetectionLab/Vagrant/resources/splunk_server/transforms.conf
2019-02-18 21:47:03 -08:00

11 lines
240 B
Plaintext

[powershell_rename_host]
DEST_KEY = MetaData:Host
SOURCE_KEY = MetaData:Source
REGEX = PowerShell_transcript\.([^\.]+)\.
FORMAT = host::$1
[wef_computername_as_host]
DEST_KEY = MetaData:Host
REGEX = (?m)ComputerName=(.+)
FORMAT = host::$1