Mappings: Alibaba ActionTrail ConsoleSignin
Input | Value |
---|---|
Vendor | Alibaba |
Product | ActionTrail |
Log Format | JSON |
Event ID Regex Pattern | ConsoleSignin.* |
Output | Value |
---|---|
Vendor | Alibaba |
Product | ActionTrail |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
accountId | userIdentity.accountId | |
action | eventName | |
application | eventSource | |
device_uniqueId | requestParameters.InstanceIds.1 | |
http_userAgent | userAgent | |
mfa | additionalEventData.mfaChecked | This is a lookup field. More info to come in the catalog later... |
normalizedAction | None | The static text logon is populated in this schema field. |
srcDevice_ip | sourceIpAddress | |
success | errorCode | This is a lookup field. More info to come in the catalog later... |
timestamp | eventTime | We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z' |
user_username | userIdentity.userName |