Skip to content

Latest commit

 

History

History
27 lines (20 loc) · 551 Bytes

0085f820-8a36-11ea-bc55-0242ac130003.md

File metadata and controls

27 lines (20 loc) · 551 Bytes

Mappings: Zeek pe Activity

Input Requirements

Input Value
Vendor Zeek
Product Zeek
Log Format JSON
Event ID Regex Pattern pe

Record Output

Output Value
Vendor Bro
Product Bro
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_hostname _system_name
threat_name _path
timestamp ts We expect the orginal record value of ts is in the format YYYY-MM-dd'T'HH:mm:ss.SSSSSSZ