Skip to content

Commit 442d24c

Browse files
authored
Fix IPv6 cleanup (elastic#10801)
* Fix IPv6 cleanup * Add tests examples * Improve regexp * Fix changelog quotes * Revert "Improve regexp" This reverts commit b7bfc7fb43da1661cb0a1745ec6e63de9c67cb29.
1 parent 7a2313f commit 442d24c

File tree

20 files changed

+108
-19
lines changed

20 files changed

+108
-19
lines changed

packages/sentinel_one_cloud_funnel/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.3.1"
3+
changes:
4+
- description: Fix IPv6 cleanup step.
5+
type: bugfix
6+
link: https://github.com/elastic/integrations/pull/10801
27
- version: "1.3.0"
38
changes:
49
- description: Allow users to split event categories into separate data streams.

packages/sentinel_one_cloud_funnel/data_stream/event/_dev/test/pipeline/test-dns.log

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

packages/sentinel_one_cloud_funnel/data_stream/event/_dev/test/pipeline/test-dns.log-expected.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -693,7 +693,7 @@
693693
],
694694
"id": "01GEF7MT4CB2DBKG1NGZ8XA7E0_105",
695695
"kind": "event",
696-
"original": "{\"timestamp\":\"18:32:29.495\",\"src.process.parent.isStorylineRoot\":true,\"event.category\":\"dns\",\"src.process.parent.image.sha1\":\"f9bc4c756eab5121ace7ec1cf6a394be0439dec0\",\"site.id\":\"123456789123456789\",\"osSrc.process.isRedirectCmdProcessor\":false,\"src.process.image.binaryIsExecutable\":true,\"src.process.parent.displayName\":\"VIERO-RMSLaunchBar\",\"osSrc.process.image.md5\":\"f905359ab27db1dda964d77442735cb8\",\"osSrc.process.crossProcessOpenProcessCount\":0,\"osSrc.process.publisher\":\"MICROSOFTWINDOWSPUBLISHER\",\"osSrc.process.crossProcessDupThreadHandleCount\":0,\"src.process.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.indicatorPersistenceCount\":0,\"src.process.parent.subsystem\":\"SYS_WIN32\",\"src.process.indicatorRansomwareCount\":0,\"src.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.crossProcessOutOfStorylineCount\":0,\"osSrc.process.image.sha1\":\"bfacfa096a56e3d149634e15e1b6470ff5a03957\",\"src.process.tgtFileCreationCount\":6,\"osSrc.process.childProcCount\":0,\"src.process.indicatorInjectionCount\":0,\"osSrc.process.indicatorReconnaissanceCount\":0,\"src.process.moduleCount\":251,\"src.process.parent.name\":\"VIERO.exe\",\"i.version\":\"preprocess-lib-1.0\",\"osSrc.process.signedStatus\":\"signed\",\"sca:atlantisIngestTime\":1664811166298,\"src.process.image.md5\":\"421f6d5ec86f6b930646321fc6ed2c46\",\"src.process.indicatorReconnaissanceCount\":0,\"src.process.storyline.id\":\"8DD23004051AA366\",\"src.process.childProcCount\":1,\"mgmt.url\":\"asdf-123.sentinelone.org\",\"src.process.crossProcessOpenProcessCount\":0,\"osSrc.process.crossProcessThreadCreateCount\":0,\"osSrc.process.moduleCount\":472,\"osSrc.process.indicatorPostExploitationCount\":0,\"osSrc.process.indicatorInfostealerCount\":0,\"src.process.subsystem\":\"SYS_WIN32\",\"meta.event.name\":\"DNS\",\"src.process.parent.integrityLevel\":\"HIGH\",\"osSrc.process.user\":\"NTAUTHORITY\\\\NETWORKSERVICE\",\"osSrc.process.image.binaryIsExecutable\":true,\"osSrc.process.tgtFileModificationCount\":0,\"src.process.indicatorExploitationCount\":0,\"osSrc.process.registryChangeCount\":0,\"src.process.parent.storyline.id\":\"8DD23004051AA366\",\"osSrc.process.netConnInCount\":0,\"i.scheme\":\"edr\",\"src.process.integrityLevel\":\"HIGH\",\"osSrc.process.indicatorInjectionCount\":0,\"osSrc.process.pid\":1340,\"site.name\":\"ASDF\",\"src.process.netConnInCount\":0,\"event.time\":1664811149495,\"account.id\":\"123456789123456789\",\"dataSource.name\":\"SentinelOne\",\"osSrc.process.crossProcessCount\":0,\"endpoint.name\":\"asdf1\",\"src.process.image.sha1\":\"d8b12c9072fdcf68ec152befb004add14b5c25b8\",\"src.process.isStorylineRoot\":false,\"src.process.parent.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\stuff\\\\stuff\\\\Application\\\\stuff\\\\stuff.exe\",\"osSrc.process.isNative64Bit\":false,\"src.process.pid\":3924,\"osSrc.process.uid\":\"73833004051AA366\",\"tgt.file.isSigned\":\"unsigned\",\"sca:ingestTime\":1664811166,\"dataSource.category\":\"security\",\"src.process.cmdline\":\"C:\\\\ProgramFiles(x86)\\\\Microsoft\\\\important_stuff\\\\stuff.EXE\\\\\",\"src.process.crossProcessThreadCreateCount\":0,\"src.process.parent.isNative64Bit\":true,\"osSrc.process.isStorylineRoot\":true,\"src.process.parent.isRedirectCmdProcessor\":false,\"osSrc.process.integrityLevel\":\"SYSTEM\",\"src.process.signedStatus\":\"unsigned\",\"src.process.crossProcessCount\":0,\"osSrc.process.subsystem\":\"SYS_WIN32\",\"event.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0_105\",\"osSrc.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.tgtFileCreationCount\":0,\"src.process.parent.cmdline\":\"\\\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\VIERO.exe\\\"\",\"src.process.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\CC.Falcon.OrderModule.exe\",\"src.process.tgtFileModificationCount\":4,\"osSrc.process.name\":\"svchost.exe\",\"src.process.indicatorEvasionCount\":26,\"src.process.netConnOutCount\":26,\"osSrc.process.startTime\":1664800506863,\"src.process.crossProcessDupThreadHandleCount\":0,\"endpoint.os\":\"windows\",\"osSrc.process.netConnOutCount\":53,\"osSrc.process.image.sha256\":\"e3d84df77b279ea288cc726cbf68867dc6ae00d24e0e24985141a2ee4753682a\",\"src.process.tgtFileDeletionCount\":6,\"src.process.startTime\":1664803358244,\"mgmt.id\":\"1337\",\"osSrc.process.indicatorRansomwareCount\":0,\"osSrc.process.netConnCount\":53,\"os.name\":\"Windows8.1Pro\",\"osSrc.process.indicatorGeneral.count\":7,\"src.process.displayName\":\"OrderEntryApplication(Client)\",\"osSrc.process.dnsCount\":6126,\"event.dns.request\":\"blog.example.com\",\"event.dns.response\":\"infra-cdn.example.com;216.160.83.57\",\"src.process.isNative64Bit\":true,\"src.process.parent.sessionId\":1,\"osSrc.process.sessionId\":0,\"src.process.uid\":\"AFD43004051AA366\",\"src.process.parent.image.md5\":\"1f3d8a05852ee60fb475e86a0ae74e27\",\"osSrc.process.verifiedStatus\":\"verified\",\"osSrc.process.cmdline\":\"C:\\\\WINDOWS\\\\system32\\\\svchost.exe-kNetworkService\",\"src.process.indicatorInfostealerCount\":0,\"src.process.indicatorBootConfigurationUpdateCount\":0,\"process.unique.key\":\"AFD43004051AA366\",\"src.process.parent.uid\":\"8CD23004051AA366\",\"agent.version\":\"22.1.2.217\",\"src.process.parent.image.sha256\":\"d2213413a6a558981670676ff0575e31542067ef69ee7e061c0308c4f0c0888d\",\"src.process.sessionId\":1,\"src.process.netConnCount\":26,\"mgmt.osRevision\":\"9600\",\"osSrc.process.image.path\":\"C:\\\\WINDOWS\\\\System32\\\\svchost.exe\",\"group.id\":\"asdf\",\"osSrc.process.indicatorBootConfigurationUpdateCount\":0,\"src.process.isRedirectCmdProcessor\":false,\"src.process.parent.startTime\":1664802966680,\"osSrc.process.indicatorExploitationCount\":0,\"src.process.dnsCount\":26,\"osSrc.process.tgtFileDeletionCount\":0,\"endpoint.type\":\"laptop\",\"osSrc.process.indicatorEvasionCount\":6,\"trace.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0\",\"src.process.name\":\"CC.Falcon.OrderModule.exe\",\"agent.uuid\":\"asdf356783457dfds4456d65\",\"osSrc.process.displayName\":\"HostProcessforWindowsServices\",\"src.process.image.sha256\":\"ca261f1061485488d08e4c4618b18b42d559f4288dbad3a5c758523347ab3e7c\",\"src.process.indicatorGeneralCount\":6,\"src.process.crossProcessOutOfStorylineCount\":0,\"src.process.registryChangeCount\":0,\"packet.id\":\"1A1DF4D521014F9C90F4CF31E5446B91\",\"src.process.indicatorPersistenceCount\":0,\"src.process.parent.signedStatus\":\"unsigned\",\"src.process.parent.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.storyline.id\":\"74833004051AA366\",\"event.type\":\"DNS Resolved\",\"src.process.indicatorPostExploitationCount\":0,\"src.process.parent.pid\":2728}",
696+
"original": "{\"timestamp\":\"18:32:29.495\",\"src.process.parent.isStorylineRoot\":true,\"event.category\":\"dns\",\"src.process.parent.image.sha1\":\"f9bc4c756eab5121ace7ec1cf6a394be0439dec0\",\"site.id\":\"123456789123456789\",\"osSrc.process.isRedirectCmdProcessor\":false,\"src.process.image.binaryIsExecutable\":true,\"src.process.parent.displayName\":\"VIERO-RMSLaunchBar\",\"osSrc.process.image.md5\":\"f905359ab27db1dda964d77442735cb8\",\"osSrc.process.crossProcessOpenProcessCount\":0,\"osSrc.process.publisher\":\"MICROSOFTWINDOWSPUBLISHER\",\"osSrc.process.crossProcessDupThreadHandleCount\":0,\"src.process.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.indicatorPersistenceCount\":0,\"src.process.parent.subsystem\":\"SYS_WIN32\",\"src.process.indicatorRansomwareCount\":0,\"src.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.crossProcessOutOfStorylineCount\":0,\"osSrc.process.image.sha1\":\"bfacfa096a56e3d149634e15e1b6470ff5a03957\",\"src.process.tgtFileCreationCount\":6,\"osSrc.process.childProcCount\":0,\"src.process.indicatorInjectionCount\":0,\"osSrc.process.indicatorReconnaissanceCount\":0,\"src.process.moduleCount\":251,\"src.process.parent.name\":\"VIERO.exe\",\"i.version\":\"preprocess-lib-1.0\",\"osSrc.process.signedStatus\":\"signed\",\"sca:atlantisIngestTime\":1664811166298,\"src.process.image.md5\":\"421f6d5ec86f6b930646321fc6ed2c46\",\"src.process.indicatorReconnaissanceCount\":0,\"src.process.storyline.id\":\"8DD23004051AA366\",\"src.process.childProcCount\":1,\"mgmt.url\":\"asdf-123.sentinelone.org\",\"src.process.crossProcessOpenProcessCount\":0,\"osSrc.process.crossProcessThreadCreateCount\":0,\"osSrc.process.moduleCount\":472,\"osSrc.process.indicatorPostExploitationCount\":0,\"osSrc.process.indicatorInfostealerCount\":0,\"src.process.subsystem\":\"SYS_WIN32\",\"meta.event.name\":\"DNS\",\"src.process.parent.integrityLevel\":\"HIGH\",\"osSrc.process.user\":\"NTAUTHORITY\\\\NETWORKSERVICE\",\"osSrc.process.image.binaryIsExecutable\":true,\"osSrc.process.tgtFileModificationCount\":0,\"src.process.indicatorExploitationCount\":0,\"osSrc.process.registryChangeCount\":0,\"src.process.parent.storyline.id\":\"8DD23004051AA366\",\"osSrc.process.netConnInCount\":0,\"i.scheme\":\"edr\",\"src.process.integrityLevel\":\"HIGH\",\"osSrc.process.indicatorInjectionCount\":0,\"osSrc.process.pid\":1340,\"site.name\":\"ASDF\",\"src.process.netConnInCount\":0,\"event.time\":1664811149495,\"account.id\":\"123456789123456789\",\"dataSource.name\":\"SentinelOne\",\"osSrc.process.crossProcessCount\":0,\"endpoint.name\":\"asdf1\",\"src.process.image.sha1\":\"d8b12c9072fdcf68ec152befb004add14b5c25b8\",\"src.process.isStorylineRoot\":false,\"src.process.parent.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\stuff\\\\stuff\\\\Application\\\\stuff\\\\stuff.exe\",\"osSrc.process.isNative64Bit\":false,\"src.process.pid\":3924,\"osSrc.process.uid\":\"73833004051AA366\",\"tgt.file.isSigned\":\"unsigned\",\"sca:ingestTime\":1664811166,\"dataSource.category\":\"security\",\"src.process.cmdline\":\"C:\\\\ProgramFiles(x86)\\\\Microsoft\\\\important_stuff\\\\stuff.EXE\\\\\",\"src.process.crossProcessThreadCreateCount\":0,\"src.process.parent.isNative64Bit\":true,\"osSrc.process.isStorylineRoot\":true,\"src.process.parent.isRedirectCmdProcessor\":false,\"osSrc.process.integrityLevel\":\"SYSTEM\",\"src.process.signedStatus\":\"unsigned\",\"src.process.crossProcessCount\":0,\"osSrc.process.subsystem\":\"SYS_WIN32\",\"event.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0_105\",\"osSrc.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.tgtFileCreationCount\":0,\"src.process.parent.cmdline\":\"\\\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\VIERO.exe\\\"\",\"src.process.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\CC.Falcon.OrderModule.exe\",\"src.process.tgtFileModificationCount\":4,\"osSrc.process.name\":\"svchost.exe\",\"src.process.indicatorEvasionCount\":26,\"src.process.netConnOutCount\":26,\"osSrc.process.startTime\":1664800506863,\"src.process.crossProcessDupThreadHandleCount\":0,\"endpoint.os\":\"windows\",\"osSrc.process.netConnOutCount\":53,\"osSrc.process.image.sha256\":\"e3d84df77b279ea288cc726cbf68867dc6ae00d24e0e24985141a2ee4753682a\",\"src.process.tgtFileDeletionCount\":6,\"src.process.startTime\":1664803358244,\"mgmt.id\":\"1337\",\"osSrc.process.indicatorRansomwareCount\":0,\"osSrc.process.netConnCount\":53,\"os.name\":\"Windows8.1Pro\",\"osSrc.process.indicatorGeneral.count\":7,\"src.process.displayName\":\"OrderEntryApplication(Client)\",\"osSrc.process.dnsCount\":6126,\"event.dns.request\":\"blog.example.com\",\"event.dns.response\":\"infra-cdn.example.com;::ffff:216.160.83.57\",\"src.process.isNative64Bit\":true,\"src.process.parent.sessionId\":1,\"osSrc.process.sessionId\":0,\"src.process.uid\":\"AFD43004051AA366\",\"src.process.parent.image.md5\":\"1f3d8a05852ee60fb475e86a0ae74e27\",\"osSrc.process.verifiedStatus\":\"verified\",\"osSrc.process.cmdline\":\"C:\\\\WINDOWS\\\\system32\\\\svchost.exe-kNetworkService\",\"src.process.indicatorInfostealerCount\":0,\"src.process.indicatorBootConfigurationUpdateCount\":0,\"process.unique.key\":\"AFD43004051AA366\",\"src.process.parent.uid\":\"8CD23004051AA366\",\"agent.version\":\"22.1.2.217\",\"src.process.parent.image.sha256\":\"d2213413a6a558981670676ff0575e31542067ef69ee7e061c0308c4f0c0888d\",\"src.process.sessionId\":1,\"src.process.netConnCount\":26,\"mgmt.osRevision\":\"9600\",\"osSrc.process.image.path\":\"C:\\\\WINDOWS\\\\System32\\\\svchost.exe\",\"group.id\":\"asdf\",\"osSrc.process.indicatorBootConfigurationUpdateCount\":0,\"src.process.isRedirectCmdProcessor\":false,\"src.process.parent.startTime\":1664802966680,\"osSrc.process.indicatorExploitationCount\":0,\"src.process.dnsCount\":26,\"osSrc.process.tgtFileDeletionCount\":0,\"endpoint.type\":\"laptop\",\"osSrc.process.indicatorEvasionCount\":6,\"trace.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0\",\"src.process.name\":\"CC.Falcon.OrderModule.exe\",\"agent.uuid\":\"asdf356783457dfds4456d65\",\"osSrc.process.displayName\":\"HostProcessforWindowsServices\",\"src.process.image.sha256\":\"ca261f1061485488d08e4c4618b18b42d559f4288dbad3a5c758523347ab3e7c\",\"src.process.indicatorGeneralCount\":6,\"src.process.crossProcessOutOfStorylineCount\":0,\"src.process.registryChangeCount\":0,\"packet.id\":\"1A1DF4D521014F9C90F4CF31E5446B91\",\"src.process.indicatorPersistenceCount\":0,\"src.process.parent.signedStatus\":\"unsigned\",\"src.process.parent.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.storyline.id\":\"74833004051AA366\",\"event.type\":\"DNS Resolved\",\"src.process.indicatorPostExploitationCount\":0,\"src.process.parent.pid\":2728}",
697697
"type": [
698698
"info",
699699
"protocol"
@@ -792,7 +792,7 @@
792792
},
793793
"dns": {
794794
"request": "blog.example.com",
795-
"response": "infra-cdn.example.com;216.160.83.57"
795+
"response": "infra-cdn.example.com;::ffff:216.160.83.57"
796796
},
797797
"endpoint": {
798798
"name": "asdf1",

packages/sentinel_one_cloud_funnel/data_stream/event/elasticsearch/ingest_pipeline/pipeline-dns.yml

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -137,7 +137,6 @@ processors:
137137
]);
138138
}
139139
} else {
140-
answer = answer.replace("::ffff:", "");
141140
ips.add(answer);
142141
}
143142
}
@@ -163,6 +162,24 @@ processors:
163162
field: error.message
164163
value: 'Processor {{{_ingest.on_failure_processor_type}}} with tag {{{_ingest.on_failure_processor_tag}}} in pipeline {{{_ingest.on_failure_pipeline}}} failed with message: {{{_ingest.on_failure_message}}}'
165164
allow_duplicates: false
165+
- foreach:
166+
field: dns.answers
167+
if: ctx.dns?.answers instanceof List
168+
ignore_failure: true
169+
processor:
170+
gsub:
171+
field: _ingest._value
172+
pattern: '::ffff:([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)'
173+
replacement: '$1'
174+
- foreach:
175+
field: dns.resolved_ip
176+
if: ctx.dns?.resolved_ip instanceof List
177+
ignore_failure: true
178+
processor:
179+
gsub:
180+
field: _ingest._value
181+
pattern: '::ffff:([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)'
182+
replacement: '$1'
166183
- foreach:
167184
field: dns.resolved_ip
168185
if: ctx.dns?.resolved_ip instanceof List

packages/sentinel_one_cloud_funnel/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
format_version: "3.0.2"
22
name: sentinel_one_cloud_funnel
33
title: SentinelOne Cloud Funnel
4-
version: "1.3.0"
4+
version: "1.3.1"
55
description: Collect logs from SentinelOne Cloud Funnel with Elastic Agent.
66
type: integration
77
categories: ["security", "edr_xdr"]

packages/sysmon_linux/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.6.3"
3+
changes:
4+
- description: Fix IPv6 cleanup step.
5+
type: bugfix
6+
link: https://github.com/elastic/integrations/pull/10801
27
- version: "1.6.2"
38
changes:
49
- description: Changed owners

packages/sysmon_linux/data_stream/log/elasticsearch/ingest_pipeline/default.yml

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -802,7 +802,6 @@ processors:
802802
]);
803803
relatedHosts.add(parts[2]);
804804
} else {
805-
answer = answer.replace("::ffff:", "");
806805
ips.add(answer);
807806
}
808807
}
@@ -819,6 +818,24 @@ processors:
819818
}
820819
ctx.related.hosts = relatedHosts;
821820
}
821+
- foreach:
822+
field: dns.answers
823+
if: ctx.dns?.answers instanceof List
824+
ignore_failure: true
825+
processor:
826+
gsub:
827+
field: _ingest._value
828+
pattern: '::ffff:([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)'
829+
replacement: '$1'
830+
- foreach:
831+
field: dns.resolved_ip
832+
if: ctx.dns?.resolved_ip instanceof List
833+
ignore_failure: true
834+
processor:
835+
gsub:
836+
field: _ingest._value
837+
pattern: '::ffff:([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)'
838+
replacement: '$1'
822839
- foreach:
823840
field: dns.resolved_ip
824841
ignore_missing: true

packages/sysmon_linux/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: sysmon_linux
22
title: Sysmon for Linux
3-
version: "1.6.2"
3+
version: "1.6.3"
44
description: Collect Sysmon Linux logs with Elastic Agent.
55
type: integration
66
categories:

packages/system/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.60.4"
3+
changes:
4+
- description: Fix IPv6 cleanup step.
5+
type: bugfix
6+
link: https://github.com/elastic/integrations/pull/10801
27
- version: "1.60.3"
38
changes:
49
- description: Fix broken query on Users Renamed

packages/system/data_stream/security/_dev/test/pipeline/test-5152.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"channel": "Security",
1919
"computer_name": "COMPUTER1.contoso.com",
2020
"event_data": {
21-
"SourceAddress": "10.47.0.122",
21+
"SourceAddress": "::ffff:10.47.0.122",
2222
"LayerRTID": "13",
2323
"LayerName": "%%14597",
2424
"DestPort": "1947",

0 commit comments

Comments
 (0)