Skip to content

Commit

Permalink
Adding tables to .script/tests/KqlvalidationsTests/CustomTables
Browse files Browse the repository at this point in the history
  • Loading branch information
joanabmartins committed Jan 30, 2024
1 parent 6a930b7 commit 0185777
Show file tree
Hide file tree
Showing 2 changed files with 194 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
{
"name": "SophosEPAlerts_CL",
"properties": [
{
"name": "TimeGenerated",
"type": "Datetime"
},
{
"name": "CustomerId",
"type": "string"
},
{
"name": "EventSeverity",
"type": "string"
},
{
"name": "EventVendor",
"type": "string"
},
{
"name": "EventType",
"type": "string"
},
{
"name": "EventProduct",
"type": "string"
},
{
"name": "event_service_event_id",
"type": "string"
},
{
"name": "EventEndTime",
"type": "datetime"
},
{
"name": "DvcAction",
"type": "string"
},
{
"name": "description",
"type": "string"
},
{
"name": "DvcHostname",
"type": "string"
},
{
"name": "EventOriginalUid",
"type": "string"
},
{
"name": "data",
"type": "dynamic"
},
{
"name": "Source",
"type": "string"
},
{
"name": "info",
"type": "dynamic"
},
{
"name": "ThreatName",
"type": "string"
},
{
"name": "threat_cleanable",
"type": "boolean"
}
]
}
121 changes: 121 additions & 0 deletions .script/tests/KqlvalidationsTests/CustomTables/SophosEPEvents_CL.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
{
"name": "SophosEPEvents_CL",
"properties": [
{
"name": "TimeGenerated",
"type": "Datetime"
},
{
"name": "EventVendor",
"type": "string"
},
{
"name": "EventProduct",
"type": "string"
},
{
"name": "EventType",
"type": "string"
},
{
"name": "amsi_threat_data",
"type": "dynamic"
},
{
"name": "appCerts",
"type": "dynamic"
},
{
"name": "AppSha256",
"type": "string"
},
{
"name": "CoreRemedyItems",
"type": "string"
},
{
"name": "CoreRemedyTotalItems",
"type": "int"
},
{
"name": "Created",
"type": "datetime"
},
{
"name": "CustomerId",
"type": "string"
},
{
"name": "details",
"type": "dynamic"
},
{
"name": "EndpointId",
"type": "string"
},
{
"name": "SrcDvcType",
"type": "string"
},
{
"name": "ThreatCategory",
"type": "string"
},
{
"name": "EventOriginalUid",
"type": "string"
},
{
"name": "ips_threat_data",
"type": "dynamic"
},
{
"name": "DvcHostname",
"type": "string"
},
{
"name": "EventMessage",
"type": "string"
},
{
"name": "EventSubType",
"type": "string"
},
{
"name": "EventSeverity",
"type": "string"
},
{
"name": "Source",
"type": "string"
},
{
"name": "source_info",
"type": "dynamic"
},
{
"name": "SrcIpAddr",
"type": "string"
},
{
"name": "ThreatName",
"type": "string"
},
{
"name": "DvcAction",
"type": "string"
},
{
"name": "DstUserSid",
"type": "string"
},
{
"name": "EventEndTime",
"type": "datetime"
},
{
"name": "whitelist_properties",
"type": "dynamic"
}
]
}

0 comments on commit 0185777

Please sign in to comment.