Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 710 Bytes

56394cfe-207b-474c-86bc-c1b658646a4b.md

File metadata and controls

30 lines (23 loc) · 710 Bytes

Mappings: Twistlock Container Runtime Audit

Input Requirements

Input Value
Vendor Twistlock
Product Twistlock
Log Format JSON
Event ID Regex Pattern container_runtime_audit

Record Output

Output Value
Vendor Twistlock
Product Twistlock
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action effect
device_hostname container_name
normalizedSeverity None The static text 1 is populated in this schema field.
threat_name msg
threat_ruleType None The static text direct is populated in this schema field.
threat_signalName msg