Mappings: Box - ADD_LOGIN_ACTIVITY_DEVICE
Input | Value |
---|---|
Vendor | Box |
Product | Box |
Log Format | JSON |
Event ID Regex Pattern | ADD_LOGIN_ACTIVITY_DEVICE |
Output | Value |
---|---|
Vendor | Box |
Product | Box |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | event_type | |
sourceUid | event_id | |
srcDevice_ip | ip_address | |
success | None | The static text true is populated in this schema field. |
timestamp | created_at | We expect the orginal record value of created_at is in the format yyyy-MM-dd'T'HH:mm:ssXXX |
user_email | created_by.login | |
user_userId | created_by.id | |
user_username | created_by.name |