Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 810 Bytes

2041eb1c-fdbf-46bd-aed9-b48047ae6962.md

File metadata and controls

30 lines (23 loc) · 810 Bytes

Mappings: Mimecast Audit Authentication Logs

Input Requirements

Input Value
Vendor Mimecast
Product Mimecast
Log Format JSON
Event ID Regex Pattern audit-authentication_logs

Record Output

Output Value
Vendor Mimecast
Product Mimecast
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action auditType
description eventInfo
normalizedAction None The static text logon is populated in this schema field.
success auditType This is a lookup field. More info to come in the catalog later...
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZZ
user_username user