diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index b96cabf9dc..ca64c6b7bd 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1258,6 +1258,19 @@ soc: - event_data.destination.port - event_data.process.executable - event_data.process.pid + ':netflow:': + - soc_timestamp + - event.dataset + - source.ip + - source.port + - destination.ip + - destination.port + - network.type + - network.transport + - network.direction + - netflow.type + - netflow.exporter.version + - observer.ip server: bindAddress: 0.0.0.0:9822 baseUrl: /