Mappings: Symantec Catch All
Input | Value |
---|---|
Vendor | Symantec |
Product | Endpoint Protection |
Log Format | JSON |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Windows |
Record Type | Endpoint |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | Action | |
device_hostname | HostName | |
device_ip | IP_Address | |
timestamp | Begin_Time | We expect the orginal record value of Begin_Time is in the format yyyy-MM-dd HH:mm:ss |
user_username | UserName |