Skip to content

Latest commit

 

History

History
27 lines (20 loc) · 719 Bytes

3d305450-6c23-4e0f-b7e1-b1b7a648f0ec.md

File metadata and controls

27 lines (20 loc) · 719 Bytes

Mappings: Microsoft Office 365 Security Compliance Center EOPCmdlet Events

Input Requirements

Input Value
Vendor Microsoft
Product Office 365
Log Format JSON
Event ID Regex Pattern SecurityComplianceCenterEOPCmdlet|18

Record Output

Output Value
Vendor Microsoft
Product Office 365
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_ip None The static text 0.0.0.0 is populated in this schema field.
timestamp CreationTime We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss
user_username UserId