Skip to content

Latest commit

 

History

History
28 lines (21 loc) · 622 Bytes

c3f3c9f3-90f5-4340-823f-7a133a278647.md

File metadata and controls

28 lines (21 loc) · 622 Bytes

Mappings: Microsoft Office 365 Sway Events

Input Requirements

Input Value
Vendor Microsoft
Product Office 365
Log Format JSON
Event ID Regex Pattern Sway|12

Record Output

Output Value
Vendor Microsoft
Product Office 365
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Operation
device_ip ClientIP
timestamp CreationTime We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss
user_username UserId