Skip to content

Latest commit

 

History

History
44 lines (37 loc) · 1.09 KB

97d61ef4-9995-4b9c-952b-02fdf518270a.md

File metadata and controls

44 lines (37 loc) · 1.09 KB

Mappings: Cloudflare - Logpush

Input Requirements

Input Value
Vendor Cloudflare
Product Logpush
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Cloudflare
Product Logpush
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId AccountID
action Action
device_ip ClientIP
dns_queryDomain QueryName
dns_queryType QueryType
dstDevice_ip OriginIP
dstPort EdgeDstPort
http_method ClientRequestMethod
http_referer ClientRequestReferer
http_response_statusCode EdgeResponseStatus
http_url https://%s%s
http_userAgent UserAgent
ipProtocol Transport
severity SecurityLevel
srcDevice_ip ClientIP
srcPort ClientSrcPort
success Action This is a lookup field. More info to come in the catalog later...
timestamp EdgeEndTimestamp We expect the orginal record value of EdgeEndTimestamp is in the format yyyy-MM-dd'T'HH:mm:ssZ
user_userId UserID
user_username Email