Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 907 Bytes

a3ddb240-92db-40fd-9f32-2277b52ac061.md

File metadata and controls

36 lines (29 loc) · 907 Bytes

Mappings: Sysdig Command JSON

Input Requirements

Input Value
Vendor Sysdig
Product Sysdig
Log Format JSON
Event ID Regex Pattern command

Record Output

Output Value
Vendor Sysdig
Product Sysdig
Record Type EndpointProcess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action type
baseImage comm
changeTarget cwd
commandLine content.fields.proc.cmdline
device_container_id containerId
device_container_name labels.container.label.io.kubernetes.container.name
device_hostname labels.host.hostName
device_k8s_namespace labels.container.label.io.kubernetes.pod.namespace
device_k8s_pod labels.kubernetes.pod.name
parentBaseImage pcomm
parentCommandLine content.fields.proc.pcmdline
user_username content.fields.ka.user.name