Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 973 Bytes

3132e5c1-7516-4f1a-9764-3befa028c15e.md

File metadata and controls

33 lines (26 loc) · 973 Bytes

Mappings: Windows - Security - 5140

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-5140

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type AuditResourceAccess

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description None The static text A network share object was accessed is populated in this schema field.
device_hostname Computer
resource EventData.ShareName
srcDevice_hostname EventData.ClientName
srcDevice_ip EventData.IpAddress
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_authDomain EventData.SubjectDomainName
user_userId EventData.SubjectUserSid
user_username EventData.SubjectUserName