Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 640 Bytes

54b3f101-a8da-4eb4-b1eb-a48efb095365.md

File metadata and controls

29 lines (22 loc) · 640 Bytes

Mappings: Symantec Catch All

Input Requirements

Input Value
Vendor Symantec
Product Endpoint Protection
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Action
device_hostname HostName
device_ip IP_Address
timestamp Begin_Time We expect the orginal record value of Begin_Time is in the format yyyy-MM-dd HH:mm:ss
user_username UserName