Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 1.22 KB

42b9be76-5dbc-4d18-97aa-6a51b188bfa5.md

File metadata and controls

36 lines (29 loc) · 1.22 KB

Mappings: Windows - Security - 4769

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-4769

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action EventData.Status This is a lookup field. More info to come in the catalog later...
application EventData.ServiceName
description None The static text A Kerberos service ticket was requested is populated in this schema field.
device_hostname Computer
dstDevice_hostname Computer
resource EventData.TicketEncryptionType This is a lookup field. More info to come in the catalog later...
srcDevice_ip EventData.IpAddress
success EventData.Status This is a lookup field. More info to come in the catalog later...
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_authDomain EventData.TargetDomainName
user_userId EventData.ServiceSid
user_username EventData.TargetUserName