Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel2
typeflat

Introduction

This table collects information about different authentication events generated by a variety of platforms.

Source tables

The information displayed is extracted from the following tables:

Expand
titleCheck source tables
  • adn.f5.bigip.apm

  • adn.f5.bigip.audit

  • app.lastpass.events

  • auth.cisco.ise

  • auth.duo.administrator.login

  • auth.duo.authentication.events

  • auth.jumpcloud.

...

auth.jumpcloud.ldap.events

...

auth.jumpcloud.mdm.events

...

auth.jumpcloud.radius.events

...

auth.jumpcloud.software.events

...

auth.jumpcloud.sso.events

...

  • all.events

  • auth.okta.events

  • auth.okta.system

  • auth.onelogin.events

  • auth.ping.federate.audit

  • auth.ping.federate.security_audit

  • auth.ping.id.mfa

  • auth.rsa.secureid.runtime

  • auth.securenvoy

  • auth.thycotic.secretserver

...

  • auth.unix

...

  • box.

...

  • all.

...

  • win

...

  • cef0.

...

box.devo_ea.events_windows

...

box.devo_ua.events_windows

...

box.unix

...

box.unix_cloudwatch

...

box.vmware.esx

...

box.win

...

box.winNxlog

...

box.win_classic

...

box.win_cloudwatch

...

box.win_hf

...

box.win_kinesis

...

box.win_nxlog

...

box.win_quest.change_auditor.leef

...

box.win_snare

...

box.win_solarwinds

...

box.win_winlogbeat

...

cef0.microsoft.microsoftWindows

...

cloud.aws.cloudtrail.events

...

cloud.aws.cloudtrail.signin

...

cloud.azure.ad.signin

...

cloud.azure.sql.audit

...

cloud.azure.vm.applicationevent

...

cloud.azure.vm.securityevent

...

cloud.azure.vm.systemevent

...

cloud.azure.vm.unix

...

cloud.gsuite.reports.login

...

cloud.office365.management_all

...

cloud.office365.oldmanagement

...

crm.salesforceobjects.loginhistory

...

db.mssql.events

...

db.oracle.audit_trail

...

ddi.infoblox.audit

...

firewall.fortinet.event.system

...

firewall.juniper.srx.system

...

firewall.paloalto.globalprotect

...

firewall.paloalto.system

...

helpdesk.zendesk.audit.logs

...

network.citrix.adc.sslvpn

...

siem.logtrust.web.connection

...

vpn.aws.client

...

vpn.cisco.asa.anyconnect

Table structure

...

  • microsoft.microsoftWindows

  • cloud.aws.cloudtrail.events

  • cloud.aws.cloudtrail.signin

  • cloud.azure.ad.signin

  • cloud.azure.sql.audit

  • cloud.gsuite.reports.login

  • cloud.office365.management

  • crm.salesforceobjects.loginhistory

  • db.mssql.events

  • db.oracle.audit_trail

  • ddi.infoblox.audit

  • firewall.all.vpn.auth

  • firewall.fortinet.event.system

  • firewall.juniper.srx.system

  • helpdesk.zendesk.audit.logs

  • network.cisco.switch

  • network.citrix.adc.sslvpn

  • siem.logtrust.web.connection

  • vpn.aws.client

  • vpn.cisco.asa.anyconnect

Table structure

This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables:

Note

Extra fields

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

Field

...

Type

Extra fields

eventdate

timestamp

...

source

str

...

action

str

...

machine

str

...

-

app

str

...

-

...

domain

str

...

-

user

str

...

srcIp

...

Field

...

Data type

...

Extra fields

...

source_ip

...

ip

...

-

...

source_hostname

...

str

...

-

ip4

srcHost

str

srcUser

str

...

-

result

str

...

message

str

...

hostchain

str

tag

str

Field transformations

Even though all source tables have several features in common, they have some particularities that make it necessary to undergo a set of transformations to harmonize them for the union table. The most common transformations comprise changes in the data type or the application of rules when several columns in the source table feed a single column in the union table. You can find below the detailed list of transformations in each source table.

Rw ui tabs macro
titleTable 1-3
tabIconbvicon-table
Rw tab
titleTables 1-

...

4

[ adn.f5.bigip.apm ] [ adn.f5.bigip.audit ] [ app.lastpass.events ] [ auth.cisco.ise ]

Anchor
adn.f5.bigip.apm
adn.f5.bigip.apm
adn.f5.bigip.apm

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

...

Code Block
"bigip-apm"

str

action

eventType

category

...

Code Block

...

(eventType = "Login") ? ((category = "allow") ? "LOGIN" : "FAILED") : (eventType = "Logout") ? 'LOGOUT' : 'N/A'

str

machine

hostName

 

str

...

app

-

...

Code Block
null('')

str

...

domain

domain

 

str

user

userName

 

str

srcIp

...

clientIp

...

 

ip4

...

srcHost

-

Code Block

...

null('')

str

...

srcUser

-

Code Block

...

null('')

str

result

eventType

category

...

Code Block

...

(eventType = "Login") ? ((category = "allow") ? "allow" : "deny") : 'N/A'

str

message

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
adn.f5.bigip.audit
adn.f5.bigip.audit
adn.f5.bigip.audit

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block

...

"bigip-audit"

str

action

status

Code Block

...

(status = "Login Success") ? 'LOGIN' : (status = "Logout Success") ? 'LOGOUT' : (status = "Login Failure") ? 'FAILED' : 'N/A'

str

machine

hostName

 

str

...

app

loginTty

 

str

...

domain

-

...

Code Block
null('')

str

user

user

 

str

...

srcIp

loginHostIp

 

ip4

...

srcHost

-

Code Block

...

null('')

str

...

srcUser

-

Code Block

...

null('')

str

result

status

 

str

message

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
auth.

...

lastpass.

...

events
auth.

...

lastpass.

...

events

...

app.

...

lastpass.

...

events

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
"

...

lastpass"

str

action

Action

...

typeCode

...

Code Block
(Action = "Failed login attempt") ? "FAILED" : "LOGIN"

str

machine

-

...

host

Code Block
null('')

str

...

app

-

...

Code Block

...

null(

...

'')

str

...

domain

-

Code Block
null('')

str

user

...

Username

 

str

srcIp

...

IP_

...

Address

...

FramedIPAddress

 

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

...

Rw tab
titleTables 4-6

...

Anchor
auth.

...

cisco.

...

ise
auth.

...

cisco.

...

ise
auth.

...

cisco.

...

ise

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

cisco-

...

ise"

str

action

...

typeCode

Code Block
(

...

typeCode in {'

...

Passed-Authentication'}) ? 'LOGIN' : (

...

typeCode in {'

...

Failed-Attempt'}) ? 'FAILED' :

...

 typeCode

str

machine

host

...

str

...

app

...

DstIp

...

Code Block

...

str(

...

DstIp)

str

...

source_ip

...

ip_address

...

 

...

ip4

...

source_hostname

...

domain

-

Code Block
null('')

str

user

...

username

email

...

ifthenelse(isnotnull(username) and not isempty(username), username, email)

...

str

UserName

str

srcIp

FramedIPAddress

ip4

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

-

...

 

...

str

Code Block
null('')

str

message

rawMessage

...

 

str

hostchain

hostchain

...

str

tag

tag

...

str

...

Rw tab
titleTables 5-8

[ auth.duo.administrator.login ] [ auth.duo.authentication.events ] [ auth.jumpcloud.all.events ] [ auth.okta.events ]

Anchor
auth.duo

...

.administrator.login
auth.duo.administrator.login
auth.duo.

...

administrator.

...

login

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"duo-

...

administrator-

...

login"

str

action

...

action

Code Block

...

(

...

action in {'

...

admin_

...

login'}) ? 'LOGIN'

...

 : (action in {'admin_login_error', '

...

admin_2fa_error'}) ? 'FAILED'

...

str

...

machine

...

host

...

 

...

str

...

application

...

application_name

...

 

...

str

...

user_domain

...

-

 : action

str

machine

host

str

app

-

Code Block
null('')

str

domain

-

Code Block
null('')

str

user

username

email

Code Block
ifthenelse(isnotnull(username) and not isempty(username), username, email)

str

srcIp

ip_address

ip4

srcHost

-

Code Block
null('')

str

...

source_hostname

...

access_device_hostname2

...

 

...

str

...

source_user

...

-

srcUser

...

user_name

...

 

...

str

...

source_ip

...

access_device_ip

...

 

...

ip4

-

Code Block
null('')

str

result

...

error

...

 

str

message

rawMessage

...

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor
auth.duo.

...

authentication.events
auth.duo.

...

authentication.events
auth.

...

duo.authentication.events

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

Code Block
"

...

source_hostname

...

-

...

null('')

...

str

...

source_user

...

-

...

null('')

...

str

...

result

...

-

duo-authentication-events"

str

action

...

action_message

...

(action_message = 'Sign-in successful') ? 'LOGIN' : action_message

...

str

...

machine

...

-

...

null('')

...

str

...

application

...

targets_id_str

...

 

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

actors_login_str

...

 

...

str

...

source_ip

...

actors_ip_address_str

...

ip4(actors_ip_address_str)

...

ip4

...

reason

Code Block
decode(reason, 'user_approved', 'LOGIN', 'valid_passcode', 'LOGIN', 'allowed_by_policy', 'LOGIN', 'bypass_user', 'LOGIN', 'locked_out', 'LOGOUT', 'invalid_passcode', 'FAILED', 'no_response', 'FAILED', 'user_cancelled', 'FAILED', 'user_disabled', 'FAILED', 'user_mistake', 'FAILED', 'call_timed_out', 'FAILED', 'no_keys_pressed', 'FAILED', 'user_marked_fraud', 'FAILED', reason)

str

machine

host

str

app

application_name

str

domain

-

Code Block
null('')

str

...

message

...

rawMessage

...

tag

...

tag

...

user

user_name

str

...

hostchain

...

hostchain

...

 

...

str

...

srcIp

access_device_ip

ip4

srcHost

access_device_hostname2

str

...

srcUser

...

-

...

titleTables 7-9

[ auth.okta.system ] [ auth.onelogin.events ] [ auth.ping.federate.audit ]

...

Code Block
null('')

str

result

result

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
auth.jumpcloud.all.events
auth.jumpcloud.all.events
auth.jumpcloud.all.events

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

...

-

...

"okta-system"

source

str

action

...

event_type

...

str

machine

system__hostname

str

app

application__name

process_name

Code Block
nvl(process_name, application__name)

str

domain

-

Code Block
null('')

str

user

username

resource__username

Code Block
nvl(resource__username, username)

str

srcIp

client_ipv4

ip4

srcHost

-

Code Block
null('')

str

srcUser

initiated_by__username

str

result

success

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
auth.okta.events
auth.okta.events
auth.okta.events

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"okta-events"

str

action

action_message

Code Block
(action_message = 'Sign-in successful') ? 'LOGIN' : 

...

str

...

machine

...

-

...

null('')

...

str

...

application

...

target_alternateId_str

...

 

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

actor_alternateId

...

 

...

str

...

source_ip

...

client_ipAddress

...

 

...

ip4

...

source_hostname

...

-

...

null('')

...

str

...

source_user

...

-

...

null('')

...

str

...

result

...

outcome_result

...

 

...

str

...

message

...

rawMessage

...

 

...

str

...

hostchain

...

hostchain

...

 

...

str

...

...

tag

...

tag

...

 

...

str

...

...

Field in union table

...

Field in source table

...

Field transformation

...

Data type

...

Extra fields

...

eventdate

...

eventdate

...

 

...

timestamp

...

source

...

-

...

"onelogin-events"

...

str

...

action

...

eventTypeId

...

Code Block
(eventTypeId = 5 or eventTypeId = 8) ? 'LOGIN' : ((eventTypeId = 7 or eventTypeId = 29) ? 'LOGOUT' : 'FAILED')

...

str

...

machine

...

hostname

...

 

...

str

...

application

...

appName

...

 

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

userName

...

 

...

str

...

source_ip

...

ipaddr

...

 

...

ip4

...

source_hostname

...

-

...

null('')

...

str

...

source_user

...

-

...

null('')

...

str

...

result

...

riskReasons

...

 

...

str

...

message

...

rawMessage

...

 

...

str

...

hostchain

...

hostchain

...

 

...

str

...

...

tag

...

tag

...

 

...

str

...

...

Field in union table

...

Field in source table

...

Field transformation

...

Data type

...

Extra fields

...

eventdate

...

eventdate

...

 

...

timestamp

...

source

...

-

...

"ping"

...

str

...

action

...

event

...

Code Block
(event in {'SSO'}) ? 'LOGIN' : (event in {'SLO'}) ? 'LOGOUT' : event

...

str

...

machine

...

pfhost

...

 

...

str

...

application

...

app

...

 

...

str

...

user_domain

...

-

action_message

str

machine

-

Code Block
null('')

str

app

targets_id_str

str

domain

-

Code Block
null('')

str

user

actors_login_str

str

srcIp

actors_ip_address_str

Code Block
ip4(actors_ip_address_str)

ip4

srcHost

-

Code Block
null('')

str

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Rw tab
titleTables 8-10

[ auth.okta.system ] [ auth.onelogin.events ] [ auth.ping.federate.audit ]

Anchor
auth.okta.system
auth.okta.system
auth.okta.system

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"okta-system"

str

action

legacyEventType

Code Block
(legacyEventType in {'app.ad.login.success', 'app.ad.agent.user_auth', 'core.user_auth.idp.saml.login_success', 'iwa.auth', 'core.user.factor.attempt_success', 'core.user_auth.radius.login.succeeded', 'app.auth.sso', 'core.user_auth.login_success', 'core.user_auth.idp.social.login_success'}) ? 'LOGIN' : (legacyEventType in {'app.ad.login.expired_password', 'app.ad.login.unknown_failure', 'app.ad.login.locked_account', 'app.ad.login.bad_password', 'app.ad.agent.user_auth.error', 'core.user_auth.idp.saml.saml_validation_failed', 'core.user_auth.idp.saml.response_received_in_response_to_no_matching_key', 'core.user_auth.idp.invalid_user_status', 'iwa.invalid_token', 'core.user.factor.attempt_fail', 'core.user_auth.radius.login.failed', 'core.user_auth.login_failed', 'app.rich_client.login_failure'}) ? 'FAILED' : legacyEventType

str

machine

-

Code Block
null('')

str

app

target_alternateId_str

str

domain

-

Code Block
null('')

str

user

...

actor_alternateId

...

str

...

srcIp

...

source_ip

...

ip

client_ipAddress

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

outcome_result

...

 

...

str

message

...

message

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

Rw tab
titleTables 10-12

...

Anchor
auth.

...

onelogin.events
auth.onelogin.events
auth.onelogin.events

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"

...

onelogin-events"

str

action

...

eventTypeId

Code Block
(

...

eventTypeId = 5 or eventTypeId = 8) ? 'LOGIN' : (

...

(eventTypeId = 7 or eventTypeId = 29) ? 'LOGOUT' : 

...

'FAILED')

str

machine

...

hostname

str

...

app

...

appName

str

...

domain

-

Code Block
null('')

str

user

...

userName

str

...

srcIp

...

ipaddr

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

riskReasons

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
auth.ping.

...

federate.

...

audit
auth.ping.

...

federate.

...

audit
auth.ping.

...

federate.

...

audit

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"ping

...

"

str

action

...

event

Code Block
(

...

event in {'SSO'}) ? 'LOGIN' : (event in 

...

{'SLO'}) ? 'LOGOUT' : event

str

machine

...

pfhost

str

...

app

...

-

...

Code Block
null('')

app

str

...

domain

-

Code Block
null('')

str

user

subject

...

str

...

srcIp

...

ip

...

-

...

ip4

...

...

srcHost

...

source_hostname

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

status

str

message

...

message

str

hostchain

hostchain

str

tag

tag

str

...

Rw tab
titleTables 11-14

[ auth.ping.federate.security_audit ] [ auth.ping.id.mfa ] [ auth.rsa.secureid.runtime ] [ auth.securenvoy ]

Anchor
auth.ping.federate.security_audit
auth.ping.federate.security_audit
auth.ping.federate.security_audit

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

ping"

str

action

...

machine

...

hostchain

...

 

...

str

...

application

...

-

...

null('')

...

str

...

user_domain

...

event

...

"LOGIN"

...

str

Code Block
(event in {'SSO'}) ? 'LOGIN' : (event in {'SLO'}) ? 'LOGOUT' : event

str

machine

host

str

app

app

str

domain

-

Code Block
null('')

str

user

...

subject

...

str

...

srcIp

...

ip

...

-

ip4

...

...

srcHost

...

-

...

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

-

...

null('')

...

status

str

message

...

message

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

...

Rw tab
titleTables 13-15

...

Anchor
auth.

...

ping.id.mfa
auth.ping.id.mfa
auth.ping.id.mfa

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

Code Block
"

...

ping-

...

id"

str

action

...

name

...

result__status

Code Block
(result__status = "SUCCESS") ? 'LOGIN' : 'FAILED'

str

machine

...

hostchain

...

split(hostchain, "=", 0)

hostname

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

...

suser

actors__name_str

str

...

srcIp

...

-

...

Code Block
ip4

...

source_hostname

...

-

...

('')

...

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

result__message

...

str

message

...

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor
auth.rsa.secureid.

...

runtime
auth.

...

rsa.secureid.runtime
auth.rsa.

...

secureid.runtime

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

...

-

...

Code Block
"securid"

str

action

...

action

result

Code Block
(result = 'SUCCESS') ? 'LOGIN' : 'FAILED'

str

machine

machine

...

 

str

...

application

app

...

category

str

domain

user_

...

-

...

security_domain_id

str

user

user_login_name

...

str

...

srcIp

...

client_ip

...

...

 

ip4

...

source_hostname

srcHost

...

hostname

str

srcUser

...

user_identity_

...

source_

...

id

...

 

str

result

...

-

...

null('')

...

result

str

message

...

message

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor

...

auth.

...

securenvoy

...

auth.

...

securenvoy

...

auth.

...

securenvoy

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

...

Code Block

...

"securenvoy"

str

action

status

...

str

...

machine

...

machineIp

...

str(machineIp)

...

str

...

application

...

sourceName

...

 

...

str

...

user_domain

...

domain

...

 

...

str

...

user

...

account

...

 

...

str

...

source_ip

...

srcIp

...

ip4(srcIp)

...

ip4

...

source_hostname

...

srcHost

...

 

...

str

...

source_user

...

subjectUsername

...

 

...

str

...

result

...

status

...

 

...

str

...

message

...

message

...

 

...

str

...

hostchain

...

hostchain

...

 

...

str

...

...

tag

...

tag

...

 

...

str

...

Rw tab
titleTables 16-19

[ cef0.microsoft.microsoftWindows ] [ cloud.aws.cloudtrail.events ] [ cloud.aws.cloudtrail.signin ] [ cloud.azure.ad.signin ]

...

-

Code Block
"LOGIN"

str

machine

hostchain

str

app

-

Code Block

...

(eventId = 512 or eventId = 4624 or eventId = 4648 or eventId = 4770) ? 'LOGIN' : (eventId = 4634) ? 'LOGOUT' : (eventId = 516 or eventId = 1210) ? 'LOCKED' : (eventId = 4768 or eventId = 4769 or eventId = 4772 or eventId = 4773) ? ((status = "0x0") ? 'LOGIN' : (status = "0x12") ? 'LOCKED' : 'FAILED') : (eventId = 4776 or eventId = 4777) ? ((status = "0x0") ? 'LOGIN' : (status = "0xC0000234") ? 'LOCKED' : 'FAILED') : 'FAILED'
null('')

str

domain

-

Code Block
null('')

str

user

client

str

srcIp

-

Code Block
ip4('')

ip4

srcHost

-

Code Block
null('')

str

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

message

str

hostchain

hostchain

str

tag

tag

str

Rw tab
titleTables 15-17

[ auth.thycotic.secretserver ] [ auth.unix ] [ box.all.win ]

Anchor
auth.thycotic.secretserver
auth.thycotic.secretserver
auth.thycotic.secretserver

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"thycotic-secretserver"

str

action

name

Code Block
(name in {"USER - LOGOUT"}) ? "LOGOUT" : (name in {"USER - LOGIN"}) ? "LOGIN" : "FAILED"

str

machine

hostchain

Code Block
split(hostchain, "=", 0)

str

app

-

Code Block
null('')

str

domain

-

Code Block
null('')

str

user

suser

str

srcIp

src

ip4

srcHost

-

Code Block
null('')

str

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

msg

str

hostchain

hostchain

str

tag

tag

str

Anchor
auth.unix
auth.unix
auth.unix

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

source

str

action

action

str

machine

machine

str

app

app

str

domain

-

Code Block
null('')

str

user

user

str

srcIp

srcIp

ip4

srcHost

srcHost

str

srcUser

srcUser

str

result

-

Code Block
null('')

str

message

message

str

hostchain

hostchain

str

tag

tag

str

Anchor
box.all.win
box.all.win
box.all.win

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

source

str

action

status

eventId

Code Block
(eventId = 512 or eventId = 4624 or eventId = 4648 or eventId = 4770 or eventId = 303) ? 'LOGIN' : (eventId = 4634) ? 'LOGOUT' : (eventId = 516 or eventId = 1210) ? 'LOCKED' : (eventId = 4768 or eventId = 4769 or eventId = 4772 or eventId = 4773) ? ((status = "0x0") ? 'LOGIN' : (status = "0x12") ? 'LOCKED' : 'FAILED') : (eventId = 4776 or eventId = 4777) ? ((status = "0x0") ? 'LOGIN' : (status = "0xC0000234") ? 'LOCKED' : 'FAILED') : 'FAILED'

str

machine

machineIp

Code Block
str(machineIp)

str

app

sourceName

str

domain

domain

str

user

account

str

srcIp

srcIp

Code Block
ip4(srcIp)

ip4

srcHost

srcHost

str

srcUser

subjectUsername

str

result

status

str

message

message

str

hostchain

hostchain

str

tag

tag

str

Rw tab
titleTables 17-20

[ cef0.microsoft.microsoftWindows ] [ cloud.aws.cloudtrail.events ] [ cloud.aws.cloudtrail.signin ] [ cloud.azure.ad.signin ]

Anchor
cef0.microsoft.microsoftWindows
cef0.microsoft.microsoftWindows
cef0.microsoft.microsoftWindows

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"microsoft-microsoft_windows"

str

action

name

str

machine

shost

str

app

deviceProcessName

str

domain

-

Code Block
null('')

str

user

duser

str

srcIp

src

ip4

srcHost

shost

str

srcUser

suser

str

result

reason

str

message

msg

str

hostchain

hostchain

str

tag

tag

str

Anchor
cloud.aws.cloudtrail.events
cloud.aws.cloudtrail.events
cloud.aws.cloudtrail.events

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"aws-cloudtrail-events"

str

action

responseElements_ConsoleLogin

Code Block
decode(responseElements_ConsoleLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements_ConsoleLogin)

str

machine

-

Code Block
null('')

str

app

-

Code Block
null('')

str

domain

-

Code Block
null('')

str

user

userIdentity_userName

str

srcIp

sourceIPAddress

Code Block
ip4(sourceIPAddress)

ip4

srcHost

requestParameters_host_str

str

srcUser

requestParameters_userName

str

result

responseElements_ConsoleLogin

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
cloud.aws.cloudtrail.signin
cloud.aws.cloudtrail.signin
cloud.aws.cloudtrail.signin

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

aws-cloudtrail-events"

str

action

...

name

...

responseElements_ConsoleLogin

Code Block
decode(responseElements_ConsoleLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements_ConsoleLogin)

str

machine

-

...

shost

Code Block
null('')

str

app

...

-

...

deviceProcessName

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

...

duser

userIdentity_userName

str

...

srcIp

...

sourceIPAddress

...

Code Block
ip4

...

source_hostname

...

shost

...

 

...

str

...

source_user

...

suser

...

(sourceIPAddress)

ip4

srcHost

requestParameters_host_str

str

srcUser

requestParameters_userName

str

result

...

responseElements_ConsoleLogin

...

 

...

str

message

...

msg

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor
cloud.

...

azure.

...

ad.

...

signin
cloud.

...

azure.

...

ad.

...

signin
cloud.

...

azure.

...

ad.

...

signin

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

...

timestamp

...

source

...

-

...

"aws-cloudtrail-events"

...

str

...

action

...

responseElements_ConsoleLogin

...

timestamp

source

-

Code Block
"aws-cloudtrail-signin"

str

action

serviceEventDetails_UserAuthentication

eventName

responseElements_ConsoleLogin

responseElements_ExternalIdPDirectoryLogin

Code Block
decode(eventName, "ConsoleLogin", decode(responseElements_ConsoleLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements_ConsoleLogin), "ExternalIdPDirectoryLogin", decode(responseElements_ExternalIdPDirectoryLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements

...

_ExternalIdPDirectoryLogin), "UserAuthentication", decode(serviceEventDetails_UserAuthentication, "Success", 'LOGIN', "Failure", 'FAILED', serviceEventDetails_UserAuthentication))

str

machine

-

Code Block
null('')

str

...

app

-

Code Block
null('')

str

...

domain

...

-

userIdentity_accountId

str

user

userIdentity_userName

...

str

...

srcIp

sourceIPAddress

Code Block
ip4(sourceIPAddress)

ip4

srcHost

...

source_hostname

...

eventSource

str

...

srcUser

...

-

...

source_user

...

requestParameters_userName

Code Block
null('')

str

result

...

-

Code Block
null('')

str

message

rawMessage

...

str

hostchain

hostchain

...

str

tag

tag

...

 

str

Rw tab
titleTables 21-24

[ cloud.azure.sql.audit ] [ cloud.gsuite.reports.login ] [ cloud.office365.management ] [ crm.salesforceobjects.loginhistory ]

Anchor
cloud.

...

azure.

...

sql.

...

audit
cloud.

...

azure.

...

sql.

...

audit
cloud.

...

azure.

...

sql.

...

audit

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

...

timestamp

...

source

...

-

...

"aws-cloudtrail-signin"

...

str

...

action

...

eventName

serviceEventDetails_UserAuthentication

responseElements_ConsoleLogin

responseElements_ExternalIdPDirectoryLogin

...

Code Block
decode(eventName, "ConsoleLogin", decode(responseElements_ConsoleLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements_ConsoleLogin), "ExternalIdPDirectoryLogin", decode(responseElements_ExternalIdPDirectoryLogin, "Success", 'LOGIN', "Failure", 'FAILED', responseElements_ExternalIdPDirectoryLogin), "UserAuthentication", decode(serviceEventDetails_UserAuthentication, "Success", 'LOGIN', "Failure", 'FAILED', serviceEventDetails_UserAuthentication))

...

str

...

machine

...

-

...

timestamp

source

-

Code Block
"azure-sql-audit"

str

action

action_id

Code Block
(action_id = "DBAF") ? 'FAILED' : 'LOGIN'

str

machine

hostname

str

app

application_name

str

domain

-

Code Block
null('')

str

user

-

Code Block
null('')

str

srcIp

client_ip

ip4

srcHost

host_name

str

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
cloud.gsuite.reports.login
cloud.gsuite.reports.login
cloud.gsuite.reports.login

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"gsuite-reports-login"

str

action

-

Code Block
null('')

str

...

application

...

-

machine

hostname

str

app

id_applicationName

str

...

domain

...

id_

...

customerId

str

user

...

actor_

...

email

...

str

...

srcIp

...

ipAddress

...

Code Block
ip4(

...

ipAddress)

ip4

...

source_hostname

...

eventSource

...

str

...

srcHost

-

Code Block
null('')

str

srcUser

actor_profileId

str

result

-

Code Block
null('')

str

message

rawMessage

...

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor
cloud.

...

office365.

...

management
cloud.

...

office365.

...

management
cloud.

...

office365.

...

application

...

properties_appDisplayName

...

 

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

identity

...

 

...

str

...

source_ip

...

callerIpAddress

...

ip4(callerIpAddress)

...

ip4

...

source_hostname

...

-

...

null('')

...

str

...

source_user

...

management

Field in union table

Field in source table

Field transformation

...

Data type

...

Extra fields

...

eventdate

...

eventdate

...

 

...

timestamp

...

source

...

-

...

"azure-ad"

...

str

...

action

...

resultType

...

(resultType = 0) ? 'LOGIN' : 'FAILED'

...

str

...

machine

...

hostchain

...

split(hostchain, "=", 0)

...

str

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"office365-management"

str

action

ResultStatus

Operation

Code Block
(Operation = "UserLoggedIn" and ResultStatus = "Success") ? 'LOGIN' : 'FAILED'

str

machine

hostname

str

app

-

Code Block
null('')

...

str

...

result

...

resultType

...

str

domain

...

-

...

rawMessage

Code Block
null('')

str

...

user

...

hostchain

UserId

str

...

srcIp

...

machine

...

hostname

...

 

...

str

...

application

...

application_name

...

 

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

-

...

null('')

...

str

...

source_ip

...

client_ip

...

 

...

ip4

...

source_hostname

...

host_name

...

 

...

str

...

source_user

...

-

...

null('')

...

str

...

result

...

-

...

null('')

...

str

...

message

...

rawMessage

...

 

...

str

...

hostchain

...

hostchain

...

ActorIpAddress

...

tag

...

 

...

str

...

Rw tab
titleTables 20-23

[ cloud.azure.sql.audit ] [ cloud.gsuite.reports.login ] [ cloud.office365.management ] [ crm.salesforceobjects.loginhistory ]

...

Field in union table

...

Field in source table

...

Field transformation

...

Data type

...

Extra fields

...

eventdate

...

eventdate

...

 

...

timestamp

...

source

...

-

...

"azure-sql-audit"

...

str

...

action

...

action_id

...

(action_id = "DBAF") ? 'FAILED' : 'LOGIN'

...

str

Code Block
ip4(ActorIpAddress)

ip4

srcHost

-

Code Block
null('')

str

srcUser

-

Code Block
null('')

str

result

ResultStatus

Operation

LogonError

Code Block
'{' + '"Operation": ' + (isnull(Operation) ? 'null' : '"' + str(Operation) + '"') + ', ' + '"LogonError": ' + (isnull(LogonError) ? 'null' : '"' + str(LogonError) + '"') + ', ' + '"ResultStatus": ' + (isnull(ResultStatus) ? 'null' : '"' + str(ResultStatus) + '"') + '}'

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

...

 

str

Anchor

...

crm.

...

salesforceobjects.

...

loginhistory

...

crm.

...

salesforceobjects.

...

loginhistory
crm.salesforceobjects.loginhistory

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

Code Block
"

...

crm.salesforceobjects.loginhistory"

str

action

Status

...

Code Block

...

(Status = "Success") ? 'LOGIN' : 'FAILED'

str

machine

hostname

...

str

...

app

...

Application

...

 

str

...

domain

...

id_customerId

-

Code Block
null('')

str

user

...

UserId

...

str

...

srcIp

...

SourceIp

...

Code Block
ip4(

...

SourceIp)

ip4

...

srcHost

-

...

null('')

...

str

...

source_user

...

actor_profileId

...

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

Status

str

message

rawMessage

...

str

hostchain

hostchain

...

str

tag

tag

...

str

Rw tab
titleTables 25-29

[ db.mssql.events ] [ db.oracle.audit_trail ] [ ddi.infoblox.audit ] [ firewall.all.vpn.auth ][ firewall.fortinet.event.system ]

Anchor

...

db.

...

mssql.

...

events

...

db.

...

mssql.

...

events

...

db.

...

mssql.

...

events

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

mssql"

str

action

...

eventID

...

Code Block
(

...

source_hostname

...

-

...

null('')

...

str

...

source_user

...

-

eventID = 18456) ? 'FAILED' : 'LOGIN'

str

machine

...

hostname

...

 

...

str

...

application

...

-

...

null('')

...

str

...

user_domain

...

-

...

null('')

...

str

...

user

...

UserId

...

 

...

str

...

source_ip

...

ActorIpAddress

...

ip4(ActorIpAddress)

...

ip4

hostname2

str

app

-

Code Block
null('')

str

...

domain

LogonError

-

ResultStatus

Code Block

...

null

...

(

...

'

...

str

...

message

...

rawMessage

...

')

str

user

user

str

srcIp

-

Code Block
ip4('')

ip4

srcHost

-

Code Block
null('')

str

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

message

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor

...

db.

...

oracle.

...

audit_trail

...

db.

...

oracle.

...

audit_trail

...

db.

...

oracle.

...

audit_trail

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

...

Code Block
"oracle-audit_trail"

str

action

...

-

...

CALCULATED_ACTION

CALCULATED_STATUS

Code Block
(CALCULATED_ACTION = "LOGIN") ? ((CALCULATED_STATUS = "SUCCESS") ? "LOGIN" : "FAILED") : "LOGOUT"

str

machine

...

hostname

USERHOST

str

app

...

-

...

Application

Code Block
null('')

str

...

source_hostname

...

 

...

Code Block
null('')

...

str

...

source_user

...

domain

-

Code Block
null('')

str

user

...

UserId

...

 

...

str

...

source_ip

...

SourceIp

...

Code Block
ip4(SourceIp)

...

ip4

CLIENT_USER

CURRENT_USER

USERID

Code Block
isnotnull(CLIENT_USER) ? CLIENT_USER : isnotnull(CURRENT_USER) ? CURRENT_USER : USERID

str

srcIp

-

Code Block
ip4('')

ip4

srcHost

USERHOST

str

srcUser

-

Code Block
null('')

str

result

...

CALCULATED_STATUS

...

 

str

message

rawMessage

...

 

str

hostchain

hostchain

...

str

tag

tag

...

str

...

Rw tab
titleTables 24-30

...

Anchor
ddi.infoblox.audit
ddi.infoblox.audit

...

ddi.infoblox.audit

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

Code Block
"

...

ddi-infoblox-audit"

str

action

action

...

eventID

...

Code Block
(action = "Login_Allowed") ? 'LOGIN' : (action = "Logout") ? 'LOGOUT' : 'FAILED'

str

machine

...

hostname2

hostname

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

admin_user

...

 

str

...

srcIp

...

srcIp

ip4

...

...

srcHost

...

-

...

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

...

-

...

null('')

...

message

str

message

...

message

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor

...

firewall.all.

...

vpn.

...

auth
firewall.all.vpn.auth
firewall.all.vpn.auth

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"

...

firewall-all-

...

vpn-

...

auth"

str

action

status

action

Code Block
ifthenelse(action = "

...

Succeeded", 'LOGIN', 'FAILED')

str

machine

...

-

Code Block
null('')

str

...

app

...

type

str

...

domain

...

-

...

fwcluster

str

user

user

str

...

srcIp

srcIp

ip4

srcHost

-

Code Block

...

null(

...

'')

...

str

...

srcUser

...

source_user

...

user

-

...

str

Code Block
null('')

str

result

...

action

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor

...

firewall.fortinet.

...

event.

...

system

...

firewall.fortinet.

...

event.

...

system

...

firewall.fortinet.

...

event.

...

system

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

fortinet-

...

event-

...

system"

str

action

status

action

Code Block
(action = 

...

"login" and status = "success") ? 'LOGIN' : (action = "

...

logout") ? 'LOGOUT' : 'FAILED'

str

machine

...

hostname

machine

str

...

application

...

...

app

method

str

...

domain

-

Code Block
null('')

str

user

...

user

...

 

str

...

srcIp

srcIp

...

Code Block
ip4

...

source_hostname

...

-

...

Code Block
null('')

...

str

...

source_user

...

-

...

(srcIp)

ip4

srcHost

devName

str

srcUser

user

str

result

...

status

...

 

str

message

rawMessage

...

 

str

hostchain

hostchain

...

str

tag

tag

str

...

tag

...

tag

...

 

...

str

...

Rw tab
titleTables 30-33

[ firewall.juniper.srx.system] [ firewall.paloalto.globalprotect ] [ firewall.paloalto.system ] [ helpdesk.zendesk.audit.logs ]

Anchor
firewall.

...

juniper.

...

srx.system
firewall.

...

juniper.

...

srx.system
firewall.

...

juniper.

...

srx.system

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

juniper-

...

srx-system"

str

action

...

log_type

...

Code Block
(

...

log_type = "

...

UI_LOGIN_EVENT") ? 'LOGIN' : (

...

log_type = "

...

UI_LOGOUT_EVENT") ? 'LOGOUT' : 'FAILED'

str

machine

machine

...

str

app

...

-

...

application

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

...

username

str

...

srcIp

client_ip

...

srcIp

ip4

...

...

srcHost

...

hostname

...

str

...

srcUser

...

-

...

source_user

...

Code Block
null('')

str

result

...

status

...

-

Code Block
null('')

str

message

...

rawMessage

message

str

hostchain

hostchain

...

str

tag

tag

...

str

Anchor
firewall.paloalto.system
firewall.paloalto.system
firewall.paloalto.globalprotect

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

 

timestamp

source

-

Code Block
"paloalto-globalprotect"

str

action

status

stage

...

Code Block
(stage = "login") ? ((status = "success") ? 'LOGIN' : 'FAILED') : (stage = "logout") ? ((status = "success") ? 'LOGOUT' : 'FAILED') : 'FAILED'

str

machine

machine

...

str

...

app

subType

str

...

domain

-

Code Block
null('')

str

user

srcuser

str

...

srcIp

public_ip

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

description

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
firewall.paloalto.system
firewall.paloalto.system
firewall.paloalto.system

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"paloalto-

...

globalprotect"

str

action

status

stage

...

eventId

Code Block
(stage = "login") ? ((status = "success") ? 'LOGIN' : 'FAILED') : (stage = "logout") ? ((status = "success") ? 'LOGOUT' : 'FAILED') : 'FAILED'

str

machine

machine

...

 

str

...

app

subType

str

...

domain

-

Code Block
null('')

str

user

...

srcuser

str

...

srcIp

...

public_ip

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

description

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

...

Anchor
helpdesk.

...

zendesk.

...

audit.

...

logs

...

helpdesk.

...

zendesk.

...

audit.

...

logs

...

helpdesk.

...

zendesk.

...

audit.

...

logs

Field in union table

Field in source table

Field transformation

...

Type

Extra

...

fields

eventdate

eventdate

...

timestamp

source

-

Code Block
"

...

helpdesk.zendesk.audit.logs"

str

action

...

log_type

...

action_label

Code Block
(action_label = "

...

Signed in") ? '

...

LOGIN' : 'FAILED'

str

machine

...

machine

-

Code Block
null('')

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

...

source_label

...

str

...

srcIp

...

ip

...

_

...

address

...

Code Block
ip4

...

source_hostname

...

hostname

...

 

...

str

...

(ip_address)

ip4

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

...

result

change_description

str

message

...

rawMessage

str

hostchain

hostchain

...

str

tag

tag

...

 

...

str

...

...

str

Rw tab
titleTables 34-38

[ network.cisco.switch ][ network.citrix.adc.sslvpn ] [ siem.logtrust.web.connection ] [ vpn.aws.client ] [ vpn.cisco.asa.anyconnect ]

Anchor
network.citrix.adc.sslvpn
network.citrix.adc.sslvpn
network.cisco.switch

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"

...

network-cisco-switch"

str

action

message

...

Code Block
(

...

message -> "pam_aaa:Authentication success") ? 'LOGIN'

...

 : 'FAILED'

...

str

machine

...

-

machine

str

...

app

...

-

...

Code Block
null('')

process

str

...

domain

-

Code Block
null('')

str

user

...

user

str

...

source_ip

srcIp

srcIp

ip4

...

...

srcHost

...

hostname

str

srcUser

...

-

Code Block
null('')

str

...

result

...

message

...

-

Code Block
null('')

str

...

result

...

change_description

...

str

message

message

str

hostchain

hostchain

str

tag

tag

...

str

...

Rw tab
titleTables 31-34

...

str

Anchor
network.citrix.adc.sslvpn
network.citrix.adc.sslvpn
network.citrix.adc.sslvpn

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"citrix-adc-sslvpn"

str

action

subtype

Code Block
(subtype = "LOGIN") ? 'LOGIN' : (subtype = "LOGOUT") ? 'LOGOUT' : 'FAILED'

str

machine

machine

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

user

str

...

srcIp

sourceIp

ip4

...

srcHost

vserverIp

Code Block
str(vserverIp)

str

...

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
siem.logtrust.web.connection
siem.logtrust.web.connection
siem.logtrust.web.connection

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"logtrust-app"

str

action

action

Code Block
(action in {'login', 'api_login', 'changedomain', 'ghost_login'}) ? 'LOGIN' : (action in {'logout', 'api_logout'}) ? 'LOGOUT' : 'FAILED'

str

machine

hostchain

Code Block
split(hostchain, "=", 0)

str

...

app

serverHost

str

...

domain

inputDomain

str

user

inputUser

str

...

srcIp

srcHost

Code Block
ip4(srcHost)

ip4

...

srcHost

srcHost

str

...

srcUser

-

Code Block
null('')

str

result

-

...

Code Block
null('')

str

message

message

action

Code Block
'ACTION: ' + action + ' MSG: ' + message

str

hostchain

hostchain

str

tag

tag

str

Anchor
vpn.aws.client
vpn.aws.client
vpn.aws.client

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"aws-vpn-client"

str

action

connection_log_type

connection_attempt_status

Code Block
(connection_log_type in {'connection-reset'} ? 'LOGOUT' : (connection_attempt_status in {'successful'} ? "LOGIN" : "FAILED"))

str

machine

hostname

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

username

str

...

srcIp

client_ip

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

connection_attempt_status

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str

Anchor
vpn.cisco.asa.anyconnect
vpn.cisco.asa.anyconnect
vpn.cisco.asa.anyconnect

Field in union table

Field in source table

Field transformation

...

Type

Extra fields

eventdate

eventdate

timestamp

source

-

Code Block
"cisco-asa-anyconnect"

str

action

EventID

Code Block
(EventID = 722022) ? 'LOGIN' : ((EventID = 722023) ? 'LOGOUT' : null(''))

str

machine

host

str

...

app

-

Code Block
null('')

str

...

domain

-

Code Block
null('')

str

user

User

str

...

srcIp

srcIP

ip4

...

srcHost

-

Code Block
null('')

str

...

srcUser

-

Code Block
null('')

str

result

-

Code Block
null('')

str

message

rawMessage

str

hostchain

hostchain

str

tag

tag

str