Mappings: SailPoint C2C Authentication Mapping
Input | Value |
---|---|
Vendor | SailPoint |
Product | SailPoint |
Log Format | JSON |
Event ID Regex Pattern | AUTHENTICATION_REQUEST_PASSED|AUTHENTICATION_REQUEST_FAILED |
Output | Value |
---|---|
Vendor | SailPoint |
Product | SailPoint |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
description | name | |
device_hostname | attributes.hostName | |
device_ip | attributes.hostName | |
normalizedAction | None | The static text logon is populated in this schema field. |
srcDevice_ip | ipAddress | |
success | technicalName | This is a lookup field. More info to come in the catalog later... |
targetUser_username | target.name | |
timestamp | created | We expect the orginal record value of created is in the format yyyy-MM-dd'T'HH:mm:ss.SSS'Z' |
user_username | actor.name |