Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 1015 Bytes

671b5df7-c62b-4c38-b12b-ace97c48f035.md

File metadata and controls

36 lines (29 loc) · 1015 Bytes

Mappings: Jamf Parser - Catch All

Input Requirements

Input Value
Vendor Jamf
Product Jamf
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Jamf
Product Jamf
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action webhook.webhookEvent
description webhook.nam
device_hostname event.computer.deviceName
device_ip event.computer.reportedIpAddress
device_mac event.computer.macAddress
device_osName event.computer.osBuild
device_uniqueId event.computer.udid
srcDevice_ip event.computer.ipAddress
success event.successful This is a lookup field. More info to come in the catalog later...
timestamp webhook.eventTimestamp We expect the orginal record value of webhook.eventTimestamp is in the format epoch
user_email event.computer.emailAddress
user_username event.computer.username