Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 987 Bytes

613e84bb-037d-4b7c-b3b6-e28ade669833.md

File metadata and controls

34 lines (27 loc) · 987 Bytes

Mappings: SailPoint C2C Authentication Mapping

Input Requirements

Input Value
Vendor SailPoint
Product SailPoint
Log Format JSON
Event ID Regex Pattern AUTHENTICATION_REQUEST_PASSED|AUTHENTICATION_REQUEST_FAILED

Record Output

Output Value
Vendor SailPoint
Product SailPoint
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
description name
device_hostname attributes.hostName
device_ip attributes.hostName
normalizedAction None The static text logon is populated in this schema field.
srcDevice_ip ipAddress
success technicalName This is a lookup field. More info to come in the catalog later...
targetUser_username target.name
timestamp created We expect the orginal record value of created is in the format yyyy-MM-dd'T'HH:mm:ss.SSS'Z'
user_username actor.name