Mappings: Linux OS Syslog - Process systemd - Systemd Session Start
Input | Value |
---|---|
Vendor | Linux |
Product | Syslog |
Log Format | JSON |
Event ID Regex Pattern | systemd-session-start |
Output | Value |
---|---|
Vendor | Linux |
Product | Linux OS Syslog |
Record Type | EndpointProcess |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
baseImage | syslog_process | |
device_hostname | syslog_hostname | |
normalizedAction | None | The static text start is populated in this schema field. |
pid | syslog_process_id | |
resource | session_id | |
user_username | user |