splunk / TA-microsoft-365-defender-advanced-hunting-add-on

13 stars 7 forks source link

Improvements on all datasets #1

Closed thilles closed 3 years ago

thilles commented 3 years ago

Additions to all datasets, more consistent naming of fields and rearrangement of lines in props.conf Added tag comments to eventtypes.conf

Tip: use view https://github.com/thilles/splunk_admin_views/blob/main/splunkadmin_cim_validation to validate and see coverage of CIM fields

inspired commented 3 years ago

Great stuff, Thomas! Thank you!