Skip to content

Commit 20df6c3

Browse files
committed
Eventtype Update
Updated Eventtype list and added tags.conf to tag eventtypes for data model use in the future.
1 parent f70329b commit 20df6c3

File tree

2 files changed

+49
-17
lines changed

2 files changed

+49
-17
lines changed
Lines changed: 29 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,27 @@
1+
[GitHub::Change]
2+
search = `github_source` action=* sourcetype="github:enterprise:audit" OR sourcetype="github_audit"
3+
4+
[GitHub::CodeScanning]
5+
search = `github_webhooks` action IN ("appeared_in_branch", "closed_by_user", "created", "fixed", "reopened", "reopened_by_user") "alert.created_at"=*
6+
7+
[GitHub::CodeVulnerability]
8+
search = `github_webhooks` (eventtype="GitHub::CodeScanning") "alert.html_url"="*/security/code-scanning/*"
9+
110
[GitHub::Issue]
211
search = `github_webhooks` action IN ("opened","edited","deleted","pinned","unpinned","closed","reopened","assigned","unassigned","labeled","unlabeled","locked","unlocked","transferred","milestoned","demilestoned") "issue.number"=* NOT "comment.body"=*
312

413
[GitHub::Issue::Comment]
514
search = `github_webhooks` action IN ("created","edited","deleted") "issue.number"=* "comment.body"=*
615

16+
[GitHub::Project]
17+
search = `github_webhooks` action IN ("created","edited","closed","reopenend","deleted") "project.number"=*
18+
19+
[GitHub::Project::Card]
20+
search = `github_webhooks` action IN ("created","edited","moved","converted","deleted") "project_card.id"=*
21+
22+
[GitHub::Project::Column]
23+
search = `github_webhooks` action IN ("created","edited","moved","deleted") "project_column.id"=*
24+
725
[GitHub::PullRequest]
826
search = `github_webhooks` action IN ("opened","edited","closed","assigned","unassigned","review_requested","review_request_removed","ready_for_review","converted_to_draft","labeled","unlabeled","synchronize","auto_merge_enabled","auto_merge_disabled","locked","unlocked","reopened") number=* "pull_request.id"=*
927

@@ -13,29 +31,23 @@ search = `github_webhooks` action IN ("submitted","edited","dismissed") pull_req
1331
[GitHub::Push]
1432
search = `github_webhooks` after=* before=* "commits{}.id"=* ref=* "pusher.name"=*
1533

16-
[GitHub::Repo]
17-
search = `github_webhooks` action IN ("created","deleted","archived","unarchived","edited","renamed","transferred","publicized","privatized") "repository.name"=* NOT "pull_request.id"=* NOT "project_card.id"=* NOT "project.number"=* NOT "project_column.id"=* NOT "check_run.id"=* NOT "alert.created_at"=* NOT "alert.number"=*
18-
19-
[GitHub::Project]
20-
search = `github_webhooks` action IN ("created","edited","closed","reopenend","deleted") "project.number"=*
21-
22-
[GitHub::Project::Card]
23-
search = `github_webhooks` action IN ("created","edited","moved","converted","deleted") "project_card.id"=*
24-
25-
[GitHub::Project::Column]
26-
search = `github_webhooks` action IN ("created","edited","moved","deleted") "project_column.id"=*
34+
[GitHub::Release]
35+
search = `github_webhooks` action IN ("released","published") release.id=*
2736

28-
[GitHub::Workflow]
29-
search = `github_webhooks` action IN ("queued","created","in_progress","completed") workflow_job.id=*
37+
[GitHub::Release::Push]
38+
search = `github_webhooks` after=* before=* ref=refs/tags*
3039

31-
[GitHub::CodeScanning]
32-
search = `github_webhooks` action IN ("appeared_in_branch", "closed_by_user", "created", "fixed", "reopened", "reopened_by_user") "alert.created_at"=*
40+
[GitHub::Repo]
41+
search = `github_webhooks` action IN ("created","deleted","archived","unarchived","edited","renamed","transferred","publicized","privatized") "repository.name"=* NOT "pull_request.id"=* NOT "project_card.id"=* NOT "project.number"=* NOT "project_column.id"=* NOT "check_run.id"=* NOT "alert.created_at"=* NOT "alert.number"=*
3342

3443
[GitHub::SecretScanning]
3544
search = `github_webhooks` action IN ("created", "resolved") "alert.secret_type"=*
3645

3746
[GitHub::VulnerabilityAlert]
3847
search = `github_webhooks` action IN ("create", "dismiss", "resolve") "alert.external_identifier"=*
3948

40-
[GitHub::Release]
41-
search = `github_webhooks` action IN ("released","published") release.id=*
49+
[GitHub::Workflow]
50+
search = `github_webhooks` action IN ("queued","created","in_progress","completed") workflow_job.id=*
51+
52+
[github:enterprise:authentication]
53+
search = `github_source` sourcetype=GithubEnterpriseServerAuditLog app=* authentication_service=* signature=*
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
[sourcetype =%20github_audit]
2+
3+
[sourcetype=github_audit]
4+
audit = enabled
5+
change = enabled
6+
7+
[eventtype=GitHub%3A%3AVulnerabilityAlert]
8+
report = enabled
9+
vulnerability = enabled
10+
11+
[eventtype=GitHub%3A%3AChange]
12+
change = enabled
13+
audit = enabled
14+
15+
[eventtype=GitHub%3A%3ACodeVulnerability]
16+
report = enabled
17+
vulnerability = enabled
18+
19+
[eventtype=github%3Aenterprise%3Aauthentication]
20+
authentication = enabled

0 commit comments

Comments
 (0)