mirror of
https://github.com/marcredhat/SIEM-toolkit-patched
synced 2026-06-08 12:33:51 +00:00
74c3a8d6a3
Selecting a source triggers a 20-event sample; actual field names from the log are merged with SDL schema defaults (log fields first) and pre-filled into the fields input. Falls back to SDL defaults if no events found. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>