Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 809 Bytes

b36d4f61-53bf-4bc7-908c-ac3db33fdb1f.md

File metadata and controls

29 lines (22 loc) · 809 Bytes

Mappings: Windows - Security - 4887

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-4887

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description None The static text Certificate Services approved a certificate request and issued a certificate is populated in this schema field.
device_hostname ccm
http_userAgent UserAgent
timestamp TimeCreated.SystemTime We expect the orginal record value of TimeCreated.SystemTime is in the format yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSSZ
user_username Requester