chronicle / detection-rules

Collection of YARA-L 2.0 sample rules for the Chronicle Detection API
https://chronicle.security
Apache License 2.0
306 stars 75 forks source link

Replace .src. with .principal. #20

Closed shapor closed 1 year ago

shapor commented 1 year ago

The correct UDM field is principal, not src, see https://cloud.google.com/chronicle/docs/unified-data-model/format-events-as-udm#specifying_nouns_entities