Splunk ES - Incoming Mapper
Maps Splunk Enterprise Security (ES) Finding and Investigation incoming fields.
Splunk Mapper (In)
Details
| ID | Splunk ES - Incoming Mapper |
|---|---|
| Type | mapping-incoming |
| Version | -1 |
| From Version | 6.2.0 |
| Default Incident Type | — |
| Feed | No |
{ "description": "Maps Splunk Enterprise Security (ES) Finding and Investigation incoming fields.", "feed": false, "id": "Splunk ES - Incoming Mapper", "mapping": { "Splunk Finding": { "dontMapEventToLabels": false, "internalMapping": { "owner": { "simple": "owner" }, "Dest": { "simple": "dest" }, "Splunk Dest Risk Object Type": { "simple": "dest_risk_object_type" }, "Splunk Dest Risk Score": { "simple": "dest_risk_score" }, "Splunk Disposition": { "simple": "disposition_label" }, "Splunk Drilldown": { "simple": "drilldown_searches" }, "Event Type": { "simple": "eventtype" }, "Host Name": { "simple": "host" }, "Event ID": { "simple": "event_id" }, "Item Owner": { "simple": "owner" }, "Source Priority": { "simple": "priority" }, "Risk Score": { "simple": "risk_score" }, "dbotMirrorDirection": { "simple": "mirror_direction" }, "dbotMirrorId": { "simple": "event_id" }, "dbotMirrorInstance": { "simple": "mirror_instance" }, "dbotMirrorTags": { "simple": "mirror_tags" }, "details": { "complex": { "filters": [], "root": "rule_description", "transformers": [ { "args": { "defaultValue": { "isContext": true, "value": { "simple": "orig_rule_description" } } }, "operator": "SetIfEmpty" }, { "args": { "defaultValue": { "isContext": true, "value": { "simple": "status_description" } } }, "operator": "SetIfEmpty" } ] } }, "Rule Name": { "simple": "rule_name" }, "name": { "complex": { "filters": [], "root": "rule_title", "transformers": [ { "args": { "defaultValue": { "isContext": true, "value": { "simple": "orig_rule_title" } } }, "operator": "SetIfEmpty" } ] } }, "Splunk Security Domain": { "complex": { "filters": [], "root": "security_domain", "transformers": [ { "args": { "defaultValue": { "isContext": true, "value": { "simple": "orig_security_domain" } } }, "operator": "SetIfEmpty" } ] } }, "Splunk Sensitivity": { "simple": "sensitivity" }, "External Severity": { "simple": "severities" }, "UUID": { "simple": "source_guid" }, "Splunk Status": { "simple": "status_label" }, "Tags": { "simple": "tag" }, "Last Update Time": { "complex": { "filters": [], "root": "review_time", "transformers": [ { "operator": "FirstArrayElement" }, { "operator": "TimeStampToDate" } ] } }, "Splunk Urgency": { "simple": "urgency" }, "Splunk Notes": { "simple": "splunk_notes" } } }, "Splunk Investigation": { "dontMapEventToLabels": false, "internalMapping": { "name": { "simple": "name" }, "occurred": { "complex": { "filters": [], "root": "create_time", "transformers": [ { "operator": "TimeStampToDate" } ] } }, "details": { "simple": "description" }, "owner": { "simple": "owner" }, "Item Owner": { "simple": "owner" }, "dbotMirrorDirection": { "simple": "mirror_direction" }, "dbotMirrorId": { "simple": "investigation_guid" }, "dbotMirrorInstance": { "simple": "mirror_instance" }, "dbotMirrorTags": { "simple": "mirror_tags" }, "Splunk Investigation GUID": { "simple": "investigation_guid" }, "Splunk Investigation ID": { "simple": "investigation_id" }, "Splunk Investigation Name": { "simple": "name" }, "Splunk Incident Origin": { "simple": "incident_origin" }, "Splunk Investigation Type": { "simple": "investigation_type" }, "Splunk Disposition": { "complex": { "filters": [], "root": "disposition_name", "transformers": [ { "args": { "defaultValue": { "isContext": true, "value": { "simple": "disposition" } } }, "operator": "SetIfEmpty" } ] } }, "Splunk Status": { "complex": { "filters": [], "root": "status_name", "transformers": [ { "args": { "defaultValue": { "isContext": true, "value": { "simple": "status" } } }, "operator": "SetIfEmpty" } ] } }, "Splunk Urgency": { "simple": "urgency" }, "Splunk Notes": { "simple": "splunk_notes" }, "Splunk Sensitivity": { "simple": "sensitivity" }, "Splunk Incident IDs": { "simple": "incident_ids" }, "Splunk Excluded Finding IDs": { "simple": "excluded_finding_ids" }, "Splunk Implicit Finding IDs": { "simple": "implicit_finding_ids" }, "Splunk Intermediate Finding IDs": { "simple": "intermediate_finding_ids" }, "Splunk Consolidated Findings": { "simple": "consolidated_findings" }, "Risk Score": { "simple": "risk_score" }, "Splunk Risk Object": { "simple": "risk_object" }, "Source IPs": { "simple": "src" }, "Destination IPs": { "simple": "dest" }, "User": { "simple": "user" }, "Last Update Time": { "complex": { "filters": [], "root": "update_time", "transformers": [ { "operator": "TimeStampToDate" } ] } }, "Splunk ES Event Type": { "simple": "splunk_es_event_type" } } } }, "name": "Splunk ES - Incoming Mapper", "type": "mapping-incoming", "version": -1, "marketplaces": [ "xsoar", "marketplacev2", "platform" ], "fromVersion": "6.2.0", "supportedModules": [ "xsiam", "agentix" ] }