diff --git a/Solutions/ForescoutHostPropertyMonitor/Analytic Rules/ForeScout-DNSSniffEventMonitor.yaml b/Solutions/ForescoutHostPropertyMonitor/Analytic Rules/ForeScout-DNSSniffEventMonitor.yaml index d116e3f09e7..15a526eb9f2 100644 --- a/Solutions/ForescoutHostPropertyMonitor/Analytic Rules/ForeScout-DNSSniffEventMonitor.yaml +++ b/Solutions/ForescoutHostPropertyMonitor/Analytic Rules/ForeScout-DNSSniffEventMonitor.yaml @@ -18,6 +18,11 @@ query: | where isnotempty(ipaddress) and isnotempty(HostProperties_EmIpAddr_s) | sort by NumEvents_d asc | project NumEvents_d, ipaddress, HostProperties_EmIpAddr_s +entityMappings: + - entityType: IP + fieldMappings: + - identifier: Address + columnName: ipaddress customDetails: Ip: ipaddress NumEvents: NumEvents_d @@ -25,5 +30,5 @@ customDetails: alertDetailsOverride: alertDisplayNameFormat: Dnsniff-Address-Check alertDescriptionFormat: Dnsniff-Address-Check alert -version: 1.0.0 +version: 1.0.1 kind: Scheduled diff --git a/Solutions/GitHub/Analytic Rules/Security Vulnerability in Repo.yaml b/Solutions/GitHub/Analytic Rules/Security Vulnerability in Repo.yaml index ea216f1a356..5004af1de9e 100644 --- a/Solutions/GitHub/Analytic Rules/Security Vulnerability in Repo.yaml +++ b/Solutions/GitHub/Analytic Rules/Security Vulnerability in Repo.yaml @@ -12,5 +12,10 @@ query: | GitHubRepo | where Action == "vulnerabilityAlert" | project TimeGenerated, DismmisedAt, Reason, vulnerableManifestFilename, Description, Link, PublishedAt, Severity, Summary -version: 1.0.1 +entityMappings: + - entityType: URL + fieldMappings: + - identifier: Url + columnName: Link +version: 1.0.2 kind: Scheduled \ No newline at end of file