diff --git a/dashboards/templates/composable/component/evtx.json b/dashboards/templates/composable/component/evtx.json index 7458ec10c..31b662520 100644 --- a/dashboards/templates/composable/component/evtx.json +++ b/dashboards/templates/composable/component/evtx.json @@ -81,6 +81,7 @@ "EventData.DnsHostName": { "type": "keyword" }, "EventData.DSName": { "type": "keyword" }, "EventData.DSType": { "type": "keyword" }, + "EventData.EffectiveConsentValue": { "type": "keyword" }, "EventData.ElevatedToken": { "type": "keyword" }, "EventData.EnabledPrivilegeList": { "type": "keyword" }, "EventData.Endpoint": { "type": "keyword" }, @@ -176,6 +177,7 @@ "EventData.NewTargetUserName": { "type": "keyword" }, "EventData.NewThreadId": { "type": "keyword" }, "EventData.NewUacValue": { "type": "keyword" }, + "EventData.NotificationType": { "type": "keyword" }, "EventData.NumberOfParameters": { "type": "integer" }, "EventData.ObjectClass": { "type": "keyword" }, "EventData.ObjectDN": { "type": "keyword" }, @@ -249,6 +251,7 @@ "EventData.RemoteMachineID": { "type": "keyword" }, "EventData.RemoteUserID": { "type": "keyword" }, "EventData.ResourceManager": { "type": "keyword" }, + "EventData.Result": { "type": "keyword" }, "EventData.ReturnCode": { "type": "keyword" }, "EventData.RuleName": { "type": "keyword" }, "EventData.SamAccountName": { "type": "keyword" },