Skip to content

Latest commit

 

History

History
28 lines (21 loc) · 795 Bytes

fd5cf2c5-3f74-458e-9052-3d53f182eef8.md

File metadata and controls

28 lines (21 loc) · 795 Bytes

Mappings: Windows - Security - 4948

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-4948

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
changeTarget EventData.RuleName
description None The static text A change was made to the Windows Firewall exception list. A rule was deleted. is populated in this schema field.
device_hostname Computer
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ