Mappings: Windows - Security - 4769
Input | Value |
---|---|
Vendor | Microsoft |
Product | Windows |
Log Format | Windows |
Event ID Regex Pattern | Security-4769 |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Windows |
Record Type | Authentication |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | EventData.Status | This is a lookup field. More info to come in the catalog later... |
application | EventData.ServiceName | |
description | None | The static text A Kerberos service ticket was requested is populated in this schema field. |
device_hostname | Computer | |
dstDevice_hostname | Computer | |
resource | EventData.TicketEncryptionType | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | EventData.IpAddress | |
success | EventData.Status | This is a lookup field. More info to come in the catalog later... |
timestamp | TimeCreated.SystemTime | We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ |
user_authDomain | EventData.TargetDomainName | |
user_userId | EventData.ServiceSid | |
user_username | EventData.TargetUserName |