Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 499 Bytes

b09d8957-f7b3-4493-8301-456c4e8bccbc.md

File metadata and controls

29 lines (22 loc) · 499 Bytes

Mappings: Auditd

Input Requirements

Input Value
Vendor Linux
Product Auditd
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Linux
Product Auditd
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description msg
device_hostname node
device_ip addr
file_path exe
user_username acct