Mappings: Microsoft Office 365 Security Compliance Center EOPCmdlet Events
Input | Value |
---|---|
Vendor | Microsoft |
Product | Office 365 |
Log Format | JSON |
Event ID Regex Pattern | SecurityComplianceCenterEOPCmdlet|18 |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Office 365 |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
device_ip | None | The static text 0.0.0.0 is populated in this schema field. |
timestamp | CreationTime | We expect the orginal record value of CreationTime is in the format yyyy-MM-dd'T'HH:mm:ss |
user_username | UserId |