Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 629 Bytes

0415ad55-fdc3-4cff-a4b0-3f148b7b7737.md

File metadata and controls

30 lines (23 loc) · 629 Bytes

Mappings: FireEye hx Malware Scan

Input Requirements

Input Value
Vendor fireeye
Product hx
Log Format CEF
Event ID Regex Pattern Malware Scan

Record Output

Output Value
Vendor FireEye
Product Endpoint Security
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action act
description msg
device_hostname dhost
device_ip dst
timestamp rt We expect the orginal record value of rt is in the format MMM dd yyyy HH:mm:ss zzz
user_username suser