Mappings: Twistlock Container Runtime Audit
Input | Value |
---|---|
Vendor | Twistlock |
Product | Twistlock |
Log Format | JSON |
Event ID Regex Pattern | container_runtime_audit |
Output | Value |
---|---|
Vendor | Twistlock |
Product | Twistlock |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | effect | |
device_hostname | container_name | |
normalizedSeverity | None | The static text 1 is populated in this schema field. |
threat_name | msg | |
threat_ruleType | None | The static text direct is populated in this schema field. |
threat_signalName | msg |