Mappings: Linux OS Syslog - Process sshd - SSH Auth Failure
Input | Value |
---|---|
Vendor | Linux |
Product | Syslog |
Log Format | JSON |
Event ID Regex Pattern | sshd-failed |
Output | Value |
---|---|
Vendor | Linux |
Product | Linux OS Syslog |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
application | tty | |
baseImage | syslog_process | |
device_hostname | syslog_hostname | |
dstDevice_hostname | syslog_hostname | |
normalizedAction | None | The static text logon is populated in this schema field. |
pid | syslog_process_id | |
srcDevice_ip | rhost | |
srcPort | source_port | |
success | None | The static text false is populated in this schema field. |
user_username | user |