Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 889 Bytes

45e49896-b546-11ea-b3de-0242ac130004.md

File metadata and controls

31 lines (24 loc) · 889 Bytes

Mappings: Windows - Security - 5139

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-5139

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type AuditChange

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
changeTarget EventData.DSName
description None The static text A directory service object was moved. is populated in this schema field.
device_hostname Computer
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_authDomain EventData.SubjectDomainName
user_userId EventData.SubjectUserSid
user_username EventData.SubjectUserName