Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 711 Bytes

1e9911a2-39d3-484a-8ce4-1e2b48759a60.md

File metadata and controls

31 lines (24 loc) · 711 Bytes

Mappings: Linux OS Syslog - Process systemd - Systemd Session Start

Input Requirements

Input Value
Vendor Linux
Product Syslog
Log Format JSON
Event ID Regex Pattern systemd-session-start

Record Output

Output Value
Vendor Linux
Product Linux OS Syslog
Record Type EndpointProcess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
baseImage syslog_process
device_hostname syslog_hostname
normalizedAction None The static text start is populated in this schema field.
pid syslog_process_id
resource session_id
user_username user