Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 809 Bytes

b1a5df95-3108-40d4-acc3-3322b0bc7688.md

File metadata and controls

32 lines (25 loc) · 809 Bytes

Mappings: Laurel Linux Audit - Catch All

Input Requirements

Input Value
Vendor Laurel
Product Laurel Linux Audit
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Laurel
Product Laurel Linux Audit
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action op
baseImage exe
description log_type This is a lookup field. More info to come in the catalog later...
device_hostname NODE
srcDevice_ip addr
success res This is a lookup field. More info to come in the catalog later...
timestamp timestamp We expect the orginal record value of timestamp is in the format epoch
user_username acct