Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 796 Bytes

c708976b-a216-48a2-a492-d6a7a4fc2529.md

File metadata and controls

32 lines (25 loc) · 796 Bytes

Mappings: Microsoft Office 365 RecordType 57

Input Requirements

Input Value
Vendor Microsoft
Product Office 365
Log Format JSON
Event ID Regex Pattern 57

Record Output

Output Value
Vendor Microsoft
Product Office 365
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Operation
application ClientApplication
commandLine AdminActionDetail
device_ip ClientIP
resourceType Workload
success ResultStatus This is a lookup field. More info to come in the catalog later...
timestamp CreationTime We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss
user_userId UserId