Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 755 Bytes

77cf5d4a-8c57-4527-890c-9536e99345de.md

File metadata and controls

31 lines (24 loc) · 755 Bytes

Mappings: Microsoft Office 365 RecordType 105

Input Requirements

Input Value
Vendor Microsoft
Product Office 365
Log Format JSON
Event ID Regex Pattern 105

Record Output

Output Value
Vendor Microsoft
Product Office 365
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Operation
device_ip ClientIP
resource ResourceId
resourceType Workload
success ResultStatus This is a lookup field. More info to come in the catalog later...
timestamp CreationTime We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss
user_userId UserId