Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 871 Bytes

f437d4e7-7b09-4f58-924e-606eb49a2418.md

File metadata and controls

33 lines (26 loc) · 871 Bytes

Mappings: Tanium Reputation Event

Input Requirements

Input Value
Vendor tanium
Product tanium
Log Format JSON
Event ID Regex Pattern reputation

Record Output

Output Value
Vendor Tanium
Product Tanium Core
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description Intel Name
device_hostname Computer Name
device_ip Computer IP
file_hash_md5 Match Details.match.properties.md5
file_hash_sha1 Match Details.match.properties.sha1
file_hash_sha256 Match Details.match.properties.sha256
file_path Match Details.match.properties.fullpath
threat_name Intel Labels
timestamp Timestamp We expect the orginal record value of Timestamp is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ