Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 1.05 KB

d7a7d607-8ed9-434d-9062-cfd6d6653c9c.md

File metadata and controls

35 lines (28 loc) · 1.05 KB

Mappings: Alibaba ActionTrail ConsoleSignin

Input Requirements

Input Value
Vendor Alibaba
Product ActionTrail
Log Format JSON
Event ID Regex Pattern ConsoleSignin.*

Record Output

Output Value
Vendor Alibaba
Product ActionTrail
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
device_uniqueId requestParameters.InstanceIds.1
http_userAgent userAgent
mfa additionalEventData.mfaChecked This is a lookup field. More info to come in the catalog later...
normalizedAction None The static text logon is populated in this schema field.
srcDevice_ip sourceIpAddress
success errorCode This is a lookup field. More info to come in the catalog later...
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_username userIdentity.userName