Mappings: Mimecast Audit Authentication Logs
Input | Value |
---|---|
Vendor | Mimecast |
Product | Mimecast |
Log Format | JSON |
Event ID Regex Pattern | audit-authentication_logs |
Output | Value |
---|---|
Vendor | Mimecast |
Product | Mimecast |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | auditType | |
description | eventInfo | |
normalizedAction | None | The static text logon is populated in this schema field. |
success | auditType | This is a lookup field. More info to come in the catalog later... |
timestamp | eventTime | We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ssZZ |
user_username | user |