Configurations (Sources): ala : Azure Sentinel ala-azure-activitylogs : Azure Activity Logs mapping for Azure Log Analytics ala-azure-ad_auditlogs : Azure AD Audit Logs mapping for Azure Log Analytics ala-azure-aws_cloudtrail : AWS CloudTrail Logs mapping for Azure Log Analytics ala-suricata : Suricata logs mapping for Azure Log Analytics arcsight : ArcSight arcsight-zeek : ArcSight Corelight Zeek and Corelight Opensource Zeek Configuration carbon-black : CarbonBlack field mapping carbon-black-eedr : CarbonBlack Enterprise EDR chronicle : Google Chronicle field mapping crowdstrike : Splunk used in Falcon Portal devo-network : Devo sourcetype mappings for network sources devo-web : Devo sourcetype mappings for web sources devo-windows : Devo sourcetype mappings for windows sources ecs-auditbeat-modules-enabled : Elastic Auditbeat (from 7.x) index pattern and field mapping ecs-auditd : Elastic Auditbeat (from 7.x) index pattern and field mapping following Elastic enabled Modules ecs-azure-activitylogs : Azure Activity Logs Elasticsearch ecs mapping ecs-azure-ad_auditlogs : Azure AD Audit Logs Elasticsearch ecs mapping ecs-azure-ad_signinlogs : Azure AD Signin Audit Logs Elasticsearch ecs mapping ecs-cloudtrail : Elastic Common Schema And Elastic Exported Fields Mapping For AWS CloudTrail Logs ecs-dns : Elastic Common Schema mapping for proxy and webserver logs including NSM DNS logs (zeek/suricata) ecs-filebeat : Elastic filebeat (from 7.x) index pattern and field mapping following Elastic Common Schema ecs-ms365_defender : Microsoft 365 Defender Elasticsearch ecs mapping ecs-okta : Elastic Exported Fields Mapping For Okta logs ecs-proxy : Elastic Common Schema mapping for proxy and webserver logs including NSM logs (zeek/suricata) ecs-suricata : Elastic Common Schema And Elastic Exported Fields Mapping For Suricata Logs ecs-zeek-corelight : Corelight Zeek and Corelight Opensource Zeek Elastic Common Schema (ECS) implementation ecs-zeek-elastic-beats-implementation : Elastic Common Schema (ECS) implementation for Zeek using filebeat modules enabled based on version 7.6.1 elk-defaultindex : ELK default indices logstash-* and filebeat-* elk-defaultindex-filebeat : ELK default indices filebeat-* elk-defaultindex-logstash : ELK default indices logstash-* elk-linux : ELK Linux Indices and Mappings elk-windows : ELK Windows Indices and Mappings elk-winlogbeat : ELK Ingested with Winlogbeat elk-winlogbeat-sp : ELK Ingested with Winlogbeat filebeat-defaultindex : Elastic Filebeat default index name fireeye-helix : FireEye Helix helk : HELK index patterns and OSSEM field mappings humio : Humio log source conditions limacharlie : LimaCharlie logpoint-windows : Logpoint logrhythm_winevent : LogRhythm Windows EventID Field Mapping logstash-defaultindex : Generic Logstash index prefix logstash-linux : Logstash Linux project (https://github.com/thomaspatzke/logstash-linux) logstash-windows : Logstash Windows common log sources logstash-zeek-default-json : Zeek field mappings for default collection of JSON logs with no parsing/normalization done and sending into logstash-*index m365 : Microsoft 365 Rules netwitness : NetWitness netwitness-epl : NetWitness powershell : Logsource to LogName mappings for PowerShell backend qradar : QRadar qualys : Qualys splunk-windows : Splunk Windows log source conditions splunk-windows-index : Splunk Windows index and EventID field mapping splunk-zeek : Splunk Zeek sourcetype mappings stix-custom : Additional STIX mapping for future use stix-shifter : Custom mappings for stix-shifter project stix2.0 : Official STIX 2.0 sumologic : SumoLogic sumologic-cse : SumoLogic sysmon : Conversion of Generic Rules into Sysmon Specific Rules thor : THOR windows-audit : Conversion for Windows Native Auditing Events winlogbeat : Elastic Winlogbeat (from 7.x) index pattern and field mapping winlogbeat-modules-enabled : Elastic Winlogbeat (from 7.x) index pattern and field mapping following Elastic enabled Modules winlogbeat-old : Elastic Winlogbeat (<=6.x) index pattern and field mapping