Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a %RecoveredRecord% column to the output profile. #1160

Closed
YamatoSecurity opened this issue Aug 15, 2023 · 0 comments · Fixed by #1164
Closed

Add a %RecoveredRecord% column to the output profile. #1160

YamatoSecurity opened this issue Aug 15, 2023 · 0 comments · Fixed by #1164
Assignees
Labels
enhancement New feature or request
Milestone

Comments

@YamatoSecurity
Copy link
Collaborator

YamatoSecurity commented Aug 15, 2023

When -x is used to recover records, I want to automatically add a %RecoveredRecord% column to the output profile.
For example, if the output profile is standard, it would change from
%Timestamp%, %Computer%, %Channel%, %EventID%, %Level%, %RecordID%, %RuleTitle%, %Details%, %ExtraFieldInfo%
to
%Timestamp%, %Computer%, %Channel%, %EventID%, %Level%, %RecordID%, %RuleTitle%, %Details%, %ExtraFieldInfo%, %RecoveredRecord%
When the record is recovered, the data should be Y (for Yes) and blank when it is just a normal record.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants