Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 623 Bytes

8db940c1-a911-4665-8c2c-39c5f56d6a5a.md

File metadata and controls

29 lines (22 loc) · 623 Bytes

Mappings: Linux OS Systemd Journal - User Command Events

Input Requirements

Input Value
Vendor Linux
Product Systemd Journal
Log Format JSON
Event ID Regex Pattern USER_CMD

Record Output

Output Value
Vendor Linux
Product Systemd Journal
Record Type EndpointProcess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
commandLine cmd
device_hostname hostname
pid pid
success res This is a lookup field. More info to come in the catalog later...
user_username auid