diff --git a/Trend Micro/trend-micro-vision-one-oat/ingest/parser.yml b/Trend Micro/trend-micro-vision-one-oat/ingest/parser.yml index d53b6c859..34b739583 100644 --- a/Trend Micro/trend-micro-vision-one-oat/ingest/parser.yml +++ b/Trend Micro/trend-micro-vision-one-oat/ingest/parser.yml @@ -1,5 +1,5 @@ name: trend-micro-vision-one-oat -ignored_values: [ ] +ignored_values: [] pipeline: - name: parsed_event external: @@ -25,8 +25,8 @@ stages: set_ecs_fields: actions: - set: - event.category: [ "intrusion_detection" ] - event.type: [ "info" ] + event.category: ["intrusion_detection"] + event.type: ["info"] observer.vendor: "TrendMicro" observer.product: "Vision One" @@ -101,8 +101,8 @@ stages: set_email_fields: actions: - set: - event.category: [ "email" ] - event.type: [ "info" ] + event.category: ["email"] + event.type: ["info"] email.from.address: "{{ parsed_event.message.suser }}" email.to.address: "{{ parsed_event.message.duser }}"