Mappings: SailPoint C2C Default Mapping
Input | Value |
---|---|
Vendor | SailPoint |
Product | SailPoint |
Log Format | JSON |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | SailPoint |
Product | SailPoint |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
changeTarget | target.name | |
description | name | |
device_hostname | attributes.hostName | |
device_ip | attributes.hostName | |
srcDevice_ip | ipAddress | |
targetUser_username | target.name | |
timestamp | created | We expect the orginal record value of created is in the format yyyy-MM-dd'T'HH:mm:ss.SSS'Z' |
user_username | attributes.accountName |