HEX

Warning: set_time_limit() [function.set-time-limit]: Cannot set time limit - prohibited by configuration in /home/u547966/brikov.ru/www/wp-content/plugins/admin-menu-editor/menu-editor.php on line 745
Server: Apache
System: Linux 4.19.0-0.bpo.9-amd64 x86_64 at red40
User: u547966 (5490)
PHP: 5.3.29-mh2
Disabled: syslog, dl, popen, proc_open, proc_nice, proc_get_status, proc_close, proc_terminate, posix_mkfifo, chown, chgrp, accelerator_reset, opcache_reset, accelerator_get_status, opcache_get_status, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_exec, pcntl_getpriority, pcntl_setpriority
Upload Files
File: //usr/share/filebeat/module/microsoft/m365_defender/config/defender.yml
{{ if eq .input "httpjson" }}

type: httpjson
config_version: "2"

interval: {{ .interval }}

auth.oauth2: {{ .oauth2 | tojson }}

{{ if .proxy_url }}
request.proxy_url: {{ .proxy_url }}
{{ end }}

request.url: "https://api.security.microsoft.com/api/incidents"
request.method: GET
request.transforms:
  - set:
      target: "header.User-Agent"
      value: "MdatpPartner-Elastic-Filebeat/1.0.0"
  - set:
      target: "url.params.$filter"
      value: 'lastUpdateTime gt [[formatDate .cursor.lastUpdateTime "2006-01-02T15:04:05.9999999Z"]]'
      default: 'lastUpdateTime gt [[formatDate (now (parseDuration "-55m")) "2006-01-02T15:04:05.9999999Z"]]'

response.split:
  target: body.value
  ignore_empty_value: true
  split:
    target: body.alerts
    keep_parent: true
    split:
      target: body.alerts.entities
      keep_parent: true

cursor:
  lastUpdateTime:
    value: "[[.last_response.body.lastUpdateTime]]"

{{ else if eq .input "file" }}

type: log
paths:
{{ range $i, $path := .paths }}
  - {{$path}}
{{ end }}
exclude_files: [".gz$"]

{{ end }}

tags: {{ .tags | tojson }}
publisher_pipeline.disable_host: {{ inList .tags "forwarded" }}

processors:
  - decode_json_fields:
      fields: [message]
      target: json
  - add_fields:
      target: ''
      fields:
        ecs.version: 1.12.0