Nessuna descrizione

local_decoder.xml 570B

123456789101112131415161718
  1. <!--
  2. SOC custom decoders (production-focused baseline)
  3. - Decodes real correlation payloads produced by SOC Integrator
  4. - Decodes real DNS IOC payloads
  5. -->
  6. <decoder name="soc-prod-dns">
  7. <prematch>soc_event=dns_ioc</prematch>
  8. <regex type="pcre2">event_type=(\S+)(?:.*?src_ip=([\d.]+))?</regex>
  9. <order>status, srcip</order>
  10. </decoder>
  11. <decoder name="soc-prod-integrator">
  12. <prematch>soc_event=correlation</prematch>
  13. <regex type="pcre2">event_type=(\S+)(?:.*?user="([^"]+)")?(?:.*?src_ip=([\d.]+))?</regex>
  14. <order>status, srcuser, srcip</order>
  15. </decoder>