Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 841 Bytes

a810cf50-7779-4555-b724-a10a92043c34.md

File metadata and controls

30 lines (23 loc) · 841 Bytes

Mappings: Google G Suite - login.gov_attack_warning

Input Requirements

Input Value
Vendor Google
Product G Suite
Log Format JSON
Event ID Regex Pattern login-attack_warning-gov_attack_warning|login.gov_attack_warning

Record Output

Output Value
Vendor Google
Product G Suite
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action events.name
description events.type
srcDevice_ip ipAddress
timestamp id.time We expect the orginal record value of id.time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ
user_email None The static text Unknown is populated in this schema field.
user_username None The static text Unknown is populated in this schema field.