Add File Access Check class #1296
Labels
enhancement
New feature or request
non_breaking
Non Breaking, backwards compatible changes
system_activity
Issues related to System Activity Category
v1.4.0 or later
Changes marked for versions beyond v1.3.0 of OCSF
Add a File Access Check class to the System category.
The Splunk private schema has this class, and it is so far there is no equivalent in the core schema. This event class is useful for the 5140 and 5145 Windows Event types.
The text was updated successfully, but these errors were encountered: