Mappings: Laurel Linux Audit - System Call
Input | Value |
---|---|
Vendor | Laurel |
Product | Laurel Linux Audit |
Log Format | JSON |
Event ID Regex Pattern | System Call.* |
Output | Value |
---|---|
Vendor | Laurel |
Product | Laurel Linux Audit |
Record Type | Endpoint |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
baseImage | SYSCALL.exe | |
commandLine | commandLine | |
description | log_type | This is a lookup field. More info to come in the catalog later... |
device_hostname | NODE | |
normalizedAction | None | The static text execute is populated in this schema field. |
parentBaseImage | PARENT_INFO.exe | |
success | SYSCALL.success | This is a lookup field. More info to come in the catalog later... |
timestamp | timestamp | We expect the orginal record value of timestamp is in the format epoch |
user_userId | SYSCALL.auid |