Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 847 Bytes

8299b68c-ac5f-40fd-b107-bd3a3705a5e7.md

File metadata and controls

33 lines (26 loc) · 847 Bytes

Mappings: AzureDevOpsAuditing

Input Requirements

Input Value
Vendor Microsoft
Product Azure
Log Format JSON
Event ID Regex Pattern AzureDevOpsAuditing

Record Output

Output Value
Vendor Microsoft
Product Azure
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action operationName
cloud_provider None The static text Azure is populated in this schema field.
cloud_service properties.loggedByService
description properties.Area
resource resourceId
srcDevice_ip callerIpAddress
timestamp time We expect the orginal record value of time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSZ
user_userId properties.ActorUserId
user_username properties.ActorUPN