Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 828 Bytes

17691d16-0d8b-4579-9fd1-c262f95b1f67.md

File metadata and controls

34 lines (27 loc) · 828 Bytes

Mappings: Linux OS Syslog - Process sshd - SSH Auth Failure

Input Requirements

Input Value
Vendor Linux
Product Syslog
Log Format JSON
Event ID Regex Pattern sshd-failed

Record Output

Output Value
Vendor Linux
Product Linux OS Syslog
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
application tty
baseImage syslog_process
device_hostname syslog_hostname
dstDevice_hostname syslog_hostname
normalizedAction None The static text logon is populated in this schema field.
pid syslog_process_id
srcDevice_ip rhost
srcPort source_port
success None The static text false is populated in this schema field.
user_username user