Mappings: Google G Suite - access_transparency/GSUITE_RESOURCE/ACCESS
Input | Value |
---|---|
Vendor | |
Product | G Suite |
Log Format | JSON |
Event ID Regex Pattern | access_transparency-GSUITE_RESOURCE-ACCESS|access_transparency.ACCESS |
Output | Value |
---|---|
Vendor | |
Product | G Suite |
Record Type | AuditResourceAccess |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | events.name | |
application | events.parameters.GSUITE_PRODUCT_NAME | |
description | events.type | |
resource | events.parameters.RESOURCE_NAME | |
sourceUid | events.parameters.LOG_ID | |
srcDevice_ip | ipAddress | |
timestamp | id.time | We expect the orginal record value of id.time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ |
user_authDomain | ownerDomain | |
user_email | actor.email | |
user_userId | actor.profileId | |
user_username | actor.email | This is a split field. More info to come in the catalog later... |