Mappings: Windows - System - 7045
Input | Value |
---|---|
Vendor | Microsoft |
Product | Windows |
Log Format | Windows |
Event ID Regex Pattern | System-7045 |
Output | Value |
---|---|
Vendor | Microsoft |
Product | Windows |
Record Type | Audit |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
application | EventData.ServiceName | |
baseImage | EventData.ImagePath | |
changeType | EventData.ServiceType | |
commandLine | EventData.ImagePath | |
description | None | The static text A new service was installed in the system is populated in this schema field. |
device_hostname | Computer | |
file_path | EventData.ImagePath | |
moduleType | EventData.StartType | |
pid | Execution.ProcessID | |
timestamp | TimeCreated.SystemTime | We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ |
user_authDomain | EventData.SubjectDomainName | |
user_userId | EventData.SubjectUserSid | |
user_username | EventData.SubjectUserName |