File tree Expand file tree Collapse file tree 3 files changed +7
-4
lines changed
uncoder-core/app/translator/mappings/platforms Expand file tree Collapse file tree 3 files changed +7
-4
lines changed Original file line number Diff line number Diff line change @@ -77,6 +77,7 @@ field_mapping:
77
77
OldTargetUserName : xdm.target.user.username
78
78
UserPrincipalName : xdm.source.user.username
79
79
DestAddress : xdm.target.ipv4
80
+ SubjectAccountName : xdm.source.user.username
80
81
SubjectUserName : xdm.source.user.username
81
82
SubjectUserSid : xdm.source.user.identifier
82
83
SourceAddr : xdm.source.ipv4
@@ -117,7 +118,6 @@ field_mapping:
117
118
method : xdm.network.http.method
118
119
notice.user_agent : xdm.network.http.browser
119
120
hasIdentity : xdm.source.user.identity_type
120
- SubjectAccountName : xdm.source.user.username
121
121
ComputerName : xdm.source.host.hostname
122
122
ExternalSeverity : xdm.alert.severity
123
123
SourceMAC : xdm.source.host.mac_addresses
Original file line number Diff line number Diff line change @@ -7,7 +7,8 @@ default_log_source:
7
7
field_mapping :
8
8
EventID : action_evtlog_event_id
9
9
Provider_Name : provider_name
10
-
10
+ SubjectAccountName : actor_effective_username
11
+
11
12
raw_log_fields :
12
13
ParentImage : regex
13
14
AccessMask : regex
Original file line number Diff line number Diff line change @@ -130,6 +130,9 @@ field_mapping:
130
130
NewValue : NewValue
131
131
Source : Source
132
132
Status : Status
133
+ SubjectAccountName :
134
+ - Subject Account Name
135
+ - SubjectAccountName
133
136
SubjectDomainName : SubjectDomainName
134
137
SubjectUserName : Target Username
135
138
SubjectUserSid : SubjectUserSid
@@ -171,5 +174,4 @@ field_mapping:
171
174
UserID : UserID
172
175
ParentProcessName : Parent Process Name
173
176
Service : Service
174
- hasIdentity : hasIdentity
175
- SubjectAccountName : SubjectAccountName
177
+ hasIdentity : hasIdentity
You can’t perform that action at this time.
0 commit comments