Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 856 Bytes

7cbbee24-8d3a-4464-b718-26159b8ed6d7.md

File metadata and controls

32 lines (25 loc) · 856 Bytes

Mappings: Endgame JSON

Input Requirements

Input Value
Vendor Endgame
Product Detection
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Endgame
Product Detection
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action type
description data.event_type_human
device_hostname endpoint.hostname
device_ip endpoint.ip_address
file_basename data.triggering_fact_array.0.data_buffer.process_name
file_hash_sha1 data.triggering_fact_array.0.data_buffer.sha1
file_hash_sha256 data.triggering_fact_array.0.data_buffer.sha256
timestamp created_at We expect the orginal record value of created_at is in the format yyyy-MM-dd'T'HH:mm:ssZ