Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 957 Bytes

402fc87e-2abc-4f24-ae5d-8978f793fb92.md

File metadata and controls

33 lines (26 loc) · 957 Bytes

Mappings: Laurel Linux Audit - System Call

Input Requirements

Input Value
Vendor Laurel
Product Laurel Linux Audit
Log Format JSON
Event ID Regex Pattern System Call.*

Record Output

Output Value
Vendor Laurel
Product Laurel Linux Audit
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
baseImage SYSCALL.exe
commandLine commandLine
description log_type This is a lookup field. More info to come in the catalog later...
device_hostname NODE
normalizedAction None The static text execute is populated in this schema field.
parentBaseImage PARENT_INFO.exe
success SYSCALL.success This is a lookup field. More info to come in the catalog later...
timestamp timestamp We expect the orginal record value of timestamp is in the format epoch
user_userId SYSCALL.auid