Skip to content

[BUG] ESCU CS fields LogonType and TargetUserName #2869

Open
@cp-sn

Description

@cp-sn

Describe the bug

There are some CS that are not using the correct field name using the last version of the "Splunk Add-on for Microsoft Windows".

Expected behavior

Some CS need to be change to the correct field names.
Field Original Name > New Name
LogonType > Logon_Type
TargetUserName > Target_User_Name > user

https://github.com/search?q=repo%3Asplunk%2Fsecurity_content+LogonType&type=code
https://github.com/search?q=repo%3Asplunk%2Fsecurity_content+TargetUserName&type=code
https://github.com/search?q=repo%3Asplunk%2Fsecurity_content+Target_User_Name&type=code

App Version:

Splunk Version 9.0.4.1
ES Content Updates 4.12.0
Enterprise Security 7.1.1

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions