Mappings: Google G Suite - login.gov_attack_warning
Input | Value |
---|---|
Vendor | |
Product | G Suite |
Log Format | JSON |
Event ID Regex Pattern | login-attack_warning-gov_attack_warning|login.gov_attack_warning |
Output | Value |
---|---|
Vendor | |
Product | G Suite |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | events.name | |
description | events.type | |
srcDevice_ip | ipAddress | |
timestamp | id.time | We expect the orginal record value of id.time is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ |
user_email | None | The static text Unknown is populated in this schema field. |
user_username | None | The static text Unknown is populated in this schema field. |