Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 825 Bytes

fa572950-571a-4570-9299-8cd3fa64fad2.md

File metadata and controls

31 lines (24 loc) · 825 Bytes

Mappings: Microsoft Office 365 AzureActiveDirectory Events

Input Requirements

Input Value
Vendor Microsoft
Product Office 365
Log Format JSON
Event ID Regex Pattern AzureActiveDirectory|8

Record Output

Output Value
Vendor Microsoft
Product Office 365
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Operation
application Workload
device_ip ActorIpAddress
success ResultStatus This is a lookup field. More info to come in the catalog later...
threat_name ExtendedProperties.auditEventCategory
timestamp CreationTime We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss
user_username UserId