CyberArk EPM Modeling Rule

Modeling Rule

CyberArk Endpoint Privilege Manager

Details

IDCyberArk_EPM_ModelingRule
From Version8.15.0
TagsCyberArk

Schema

cyberark_epm_raw

Field Type Array?
Administrator string
Description string
Feature string
InternalSessionId int
LoggedFrom string
PermissionDescription string
Role string
SetName string
accessAction string
accessTargetName string
accessTargetType string
agentId string
bundleName string
bundleVersion string
commandInfo string
computerName string
eventType string
fileName string
filePath string
fileSize int
logonAttemptTypeId int
logonStatusId int
operatingSystemType string
originUserUID string
packageName string
policyAction string
policyName string
processCommandLine string
productName string
productVersion string
publisher string
runAsUsername string
sourceProcessCommandLine string
sourceProcessHash string
sourceProcessSigner string
sourceProcessUsername string
sourceWSIp string
sourceWSName string
source_log_type string
threatProtectionAction string
userName string
winEventRecordId int
winEventType int
fromversion: 8.15.0
id: CyberArk_EPM_ModelingRule
name: CyberArk EPM Modeling Rule
rules: ''
schema: ''
tags: CyberArk
supportedModules:
- xsiam