Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 1.03 KB

940be854-b545-11ea-b3de-0242ac130004.md

File metadata and controls

32 lines (25 loc) · 1.03 KB

Mappings: Windows - Security - 4737

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-4737

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type AuditChange

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
changeTarget EventData.GroupName
changeType None The static text Security-enabled global group changed is populated in this schema field.
description None The static text This event generates every time a security-enabled (security) global group is changed. is populated in this schema field.
device_hostname Computer
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_authDomain EventData.SubjectDomainName
user_userId EventData.SubjectUserSid
user_username EventData.SubjectUserName