Closed dominiklohmann closed 4 years ago
Good catch @dominiklohmann ! Thank you very much :)
ohh wait. I just looked at the Sysmon schema (latest V11.0) and it is with lowercase https://github.com/hunters-forge/OSSEM/blob/master/resources/schemas/sysmonv11.0_4.30.xml#L84 🤔 What version of Sysmon are you running? I do not have a box to test it at the moment. Would you mind testing it with latest version?
We do have box running Sysmon, which is how we discovered the discrepancy. We'll check the version and will get back.
We're running 11, just confirmed it. The output uses a lowercase n
.
We're running 11, just confirmed it. The output uses a lowercase
n
.
@dominiklohmann, @mavam thanks for the PR. I had missed that typo when converting the data dictionaries to YAML.
The actual field name is
DestinationHostname
, notDestinationHostName
.