Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 743 Bytes

b41d7889-29cb-4afe-b675-c0b3ddf99a1f.md

File metadata and controls

31 lines (24 loc) · 743 Bytes

Mappings: PingFederate - Authentication Event

Input Requirements

Input Value
Vendor PingIdentity
Product PingFederate
Log Format JSON
Event ID Regex Pattern AUTHN_ATTEMPT|SSO

Record Output

Output Value
Vendor PingIdentity
Product PingFederate
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action event
application protocol
device_hostname host
normalizedAction None The static text logon is populated in this schema field.
srcDevice_ip ip
success status This is a lookup field. More info to come in the catalog later...
user_username subject