Skip to content

Latest commit

 

History

History
31 lines (28 loc) · 1.14 KB

EventId-15.md

File metadata and controls

31 lines (28 loc) · 1.14 KB

Event ID: 15 - FileCreateStreamHash

Native field name OSSEM Field Name
RuleName tag
UtcTime event_date_creation
ProcessGuid process_guid
ProcessId process_id
Image process_path
TargetFileName file_name
CreationUtcTime file_creation_time
Hash sysmon_hash

Logstash pipeline

if [event_id] == 15 {
      mutate {
        rename => {
            "RuleName" => "tag"
            "UtcTime" => "event_date_creation"
            "ProcessGuid" => "process_guid"
            "ProcessId" => "process_id"
            "Image" => "process_path"
            "TargetFileName" => "file_name"
            "CreationUtcTime" => "file_creation_time"
            "Hash" => "sysmon_hash"
        }
      }
    }