Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 770 Bytes

2178bcca-c3a7-443b-be3c-bdbc7f3f2154.md

File metadata and controls

30 lines (23 loc) · 770 Bytes

Mappings: Cisco ISE Events

Input Requirements

Input Value
Vendor cisco_ise
Product cisco_ise
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Cisco Systems
Product Identity Services Engine
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_hostname AD-User-Qualified-Name
normalizedAction None The static text logon is populated in this schema field.
srcDevice_hostname AD-User-Qualified-Name
success None The static text true is populated in this schema field.
user_authDomain AD-Host-DNS-Domain
user_username AD-User-SamAccount-Name