Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 836 Bytes

6ab9d7bc-aa9a-43a7-b4a6-6fd4596bab6a.md

File metadata and controls

33 lines (26 loc) · 836 Bytes

Mappings: RSA SecurID Runtime Bad Tokencode

Input Requirements

Input Value
Vendor RSA
Product SecurID Runtime
Log Format JSON
Event ID Regex Pattern AUTH_FAILED_BAD_TOKENCODE_GOOD_PIN

Record Output

Output Value
Vendor RSA
Product SecurID Runtime
Record Type Authentication

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action result_key
device_hostname agent_name
device_ip agent_ip
dstDevice_ip server_node_ip
logonType authmethod_name
normalizedAction None The static text logon is populated in this schema field.
srcDevice_ip client_ip
success action_result This is a lookup field. More info to come in the catalog later...
user_username actor_login_uid