Mappings: Microsoft Graph Security API C2C
Input | Value |
---|---|
Vendor | Microsoft |
Product | Graph Security API |
Log Format | JSON |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Graph Security API |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
accountId | userStates.1.aadUserId | |
description | description | |
device_hostname | hostStates.1.fqdn | |
device_ip | hostStates.1.privateIpAddress | |
device_uniqueId | azureTenantId | |
normalizedSeverity | severity | This is a lookup field. More info to come in the catalog later... |
threat_category | category | |
threat_identifier | vendorInformation.provider | |
threat_name | title | |
threat_ruleType | None | The static text direct is populated in this schema field. |
threat_signalName | %s - %s | |
timestamp | eventDateTime | We expect the orginal record value of eventDateTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSZ |
user_username | userStates.1.accountName |