Splunk ES - Incoming Mapper

Maps Splunk Enterprise Security (ES) Finding and Investigation incoming fields.

Splunk Mapper (In)

Details

IDSplunk ES - Incoming Mapper
Typemapping-incoming
Version-1
From Version6.2.0
Default Incident Type
FeedNo
{
    "description": "Maps Splunk Enterprise Security (ES) Finding and Investigation incoming fields.",
    "feed": false,
    "id": "Splunk ES - Incoming Mapper",
    "mapping": {
        "Splunk Finding": {
            "dontMapEventToLabels": false,
            "internalMapping": {
                "owner": {
                    "simple": "owner"
                },
                "Dest": {
                    "simple": "dest"
                },
                "Splunk Dest Risk Object Type": {
                    "simple": "dest_risk_object_type"
                },
                "Splunk Dest Risk Score": {
                    "simple": "dest_risk_score"
                },
                "Splunk Disposition": {
                    "simple": "disposition_label"
                },
                "Splunk Drilldown": {
                    "simple": "drilldown_searches"
                },
                "Event Type": {
                    "simple": "eventtype"
                },
                "Host Name": {
                    "simple": "host"
                },
                "Event ID": {
                    "simple": "event_id"
                },
                "Item Owner": {
                    "simple": "owner"
                },
                "Source Priority": {
                    "simple": "priority"
                },
                "Risk Score": {
                    "simple": "risk_score"
                },
                "dbotMirrorDirection": {
                    "simple": "mirror_direction"
                },
                "dbotMirrorId": {
                    "simple": "event_id"
                },
                "dbotMirrorInstance": {
                    "simple": "mirror_instance"
                },
                "dbotMirrorTags": {
                    "simple": "mirror_tags"
                },
                "details": {
                    "complex": {
                        "filters": [],
                        "root": "rule_description",
                        "transformers": [
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "orig_rule_description"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            },
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "status_description"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            }
                        ]
                    }
                },
                "Rule Name": {
                    "simple": "rule_name"
                },
                "name": {
                    "complex": {
                        "filters": [],
                        "root": "rule_title",
                        "transformers": [
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "orig_rule_title"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            }
                        ]
                    }
                },
                "Splunk Security Domain": {
                    "complex": {
                        "filters": [],
                        "root": "security_domain",
                        "transformers": [
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "orig_security_domain"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            }
                        ]
                    }
                },
                "Splunk Sensitivity": {
                    "simple": "sensitivity"
                },
                "External Severity": {
                    "simple": "severities"
                },
                "UUID": {
                    "simple": "source_guid"
                },
                "Splunk Status": {
                    "simple": "status_label"
                },
                "Tags": {
                    "simple": "tag"
                },
                "Last Update Time": {
                    "complex": {
                        "filters": [],
                        "root": "review_time",
                        "transformers": [
                            {
                                "operator": "FirstArrayElement"
                            },
                            {
                                "operator": "TimeStampToDate"
                            }
                        ]
                    }
                },
                "Splunk Urgency": {
                    "simple": "urgency"
                },
                "Splunk Notes": {
                    "simple": "splunk_notes"
                }
            }
        },
        "Splunk Investigation": {
            "dontMapEventToLabels": false,
            "internalMapping": {
                "name": {
                    "simple": "name"
                },
                "occurred": {
                    "complex": {
                        "filters": [],
                        "root": "create_time",
                        "transformers": [
                            {
                                "operator": "TimeStampToDate"
                            }
                        ]
                    }
                },
                "details": {
                    "simple": "description"
                },
                "owner": {
                    "simple": "owner"
                },
                "Item Owner": {
                    "simple": "owner"
                },
                "dbotMirrorDirection": {
                    "simple": "mirror_direction"
                },
                "dbotMirrorId": {
                    "simple": "investigation_guid"
                },
                "dbotMirrorInstance": {
                    "simple": "mirror_instance"
                },
                "dbotMirrorTags": {
                    "simple": "mirror_tags"
                },
                "Splunk Investigation GUID": {
                    "simple": "investigation_guid"
                },
                "Splunk Investigation ID": {
                    "simple": "investigation_id"
                },
                "Splunk Investigation Name": {
                    "simple": "name"
                },
                "Splunk Incident Origin": {
                    "simple": "incident_origin"
                },
                "Splunk Investigation Type": {
                    "simple": "investigation_type"
                },
                "Splunk Disposition": {
                    "complex": {
                        "filters": [],
                        "root": "disposition_name",
                        "transformers": [
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "disposition"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            }
                        ]
                    }
                },
                "Splunk Status": {
                    "complex": {
                        "filters": [],
                        "root": "status_name",
                        "transformers": [
                            {
                                "args": {
                                    "defaultValue": {
                                        "isContext": true,
                                        "value": {
                                            "simple": "status"
                                        }
                                    }
                                },
                                "operator": "SetIfEmpty"
                            }
                        ]
                    }
                },
                "Splunk Urgency": {
                    "simple": "urgency"
                },
                "Splunk Notes": {
                    "simple": "splunk_notes"
                },
                "Splunk Sensitivity": {
                    "simple": "sensitivity"
                },
                "Splunk Incident IDs": {
                    "simple": "incident_ids"
                },
                "Splunk Excluded Finding IDs": {
                    "simple": "excluded_finding_ids"
                },
                "Splunk Implicit Finding IDs": {
                    "simple": "implicit_finding_ids"
                },
                "Splunk Intermediate Finding IDs": {
                    "simple": "intermediate_finding_ids"
                },
                "Splunk Consolidated Findings": {
                    "simple": "consolidated_findings"
                },
                "Risk Score": {
                    "simple": "risk_score"
                },
                "Splunk Risk Object": {
                    "simple": "risk_object"
                },
                "Source IPs": {
                    "simple": "src"
                },
                "Destination IPs": {
                    "simple": "dest"
                },
                "User": {
                    "simple": "user"
                },
                "Last Update Time": {
                    "complex": {
                        "filters": [],
                        "root": "update_time",
                        "transformers": [
                            {
                                "operator": "TimeStampToDate"
                            }
                        ]
                    }
                },
                "Splunk ES Event Type": {
                    "simple": "splunk_es_event_type"
                }
            }
        }
    },
    "name": "Splunk ES - Incoming Mapper",
    "type": "mapping-incoming",
    "version": -1,
    "marketplaces": [
        "xsoar",
        "marketplacev2",
        "platform"
    ],
    "fromVersion": "6.2.0",
    "supportedModules": [
        "xsiam",
        "agentix"
    ]
}