olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.13k stars 178 forks source link

host_fqdn not generating and matches props.conf #116

Closed DerF66 closed 1 year ago

DerF66 commented 1 year ago

i am seeing Computer when XML and ComputerName when Not XML field in my logs in the windows index, It matches the props.conf. but it would not create a host_fqdn as I do not see that field on my threathunting index. This cause my overview dashboard to not work. If I delete the host_fqdn = 'none", i get a hit.