Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 695 Bytes

b34ed686-f195-4c21-a688-1141ab8a71ec.md

File metadata and controls

33 lines (26 loc) · 695 Bytes

Mappings: CrowdStrike FDR - NetworkConnectIP6

Input Requirements

Input Value
Vendor CrowdStrike
Product FDR
Log Format JSON
Event ID Regex Pattern NetworkConnectIP6

Record Output

Output Value
Vendor CrowdStrike
Product FDR
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_hostname aid
device_ip aip
device_uniqueId aid
dstDevice_ip dstIP
dstPort dstPort
ipProtocol Protocol This is a lookup field. More info to come in the catalog later...
severity severity
srcDevice_ip srcIP
srcPort srcPort