Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 1.01 KB

3e425ff8-fd24-42ac-9542-e6c6bf84e76d.md

File metadata and controls

35 lines (28 loc) · 1.01 KB

Mappings: Google G Suite - access_transparency/GSUITE_RESOURCE/ACCESS

Input Requirements

Input Value
Vendor Google
Product G Suite
Log Format JSON
Event ID Regex Pattern access_transparency-GSUITE_RESOURCE-ACCESS|access_transparency.ACCESS

Record Output

Output Value
Vendor Google
Product G Suite
Record Type AuditResourceAccess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action events.name
application events.parameters.GSUITE_PRODUCT_NAME
description events.type
resource events.parameters.RESOURCE_NAME
sourceUid events.parameters.LOG_ID
srcDevice_ip ipAddress
timestamp id.time We expect the orginal record value of id.time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ
user_authDomain ownerDomain
user_email actor.email
user_userId actor.profileId
user_username actor.email This is a split field. More info to come in the catalog later...