Azure-Sentinel/Sample Data/CEF/Forcepoint CASB.csv

6.0 KiB

1TenantIdSourceSystemTimeGeneratedReceiptTimeDeviceVendorDeviceProductDeviceEventClassIDLogSeverityOriginalLogSeverityDeviceActionSimplifiedDeviceActionComputerCommunicationDirectionDeviceFacilityDestinationPortDestinationIPDeviceAddressDeviceNameMessageProtocolSourcePortSourceIPRemoteIPRemotePortMaliciousIPThreatSeverityIndicatorThreatTypeThreatDescriptionThreatConfidenceReportReferenceLinkMaliciousIPLongitudeMaliciousIPLatitudeMaliciousIPCountryDeviceVersionActivityApplicationProtocolEventCountDestinationDnsDomainDestinationServiceNameDestinationTranslatedAddressDestinationTranslatedPortDeviceDnsDomainDeviceExternalIDDeviceInboundInterfaceDeviceNtDomainDeviceOutboundInterfaceDevicePayloadIdProcessNameDeviceTranslatedAddressDestinationHostNameDestinationMACAddressDestinationNTDomainDestinationProcessIdDestinationUserPrivilegesDestinationProcessNameDeviceTimeZoneDestinationUserIDDestinationUserNameDeviceMacAddressProcessIDExternalIDFileCreateTimeFileHashFileIDFileModificationTimeFilePathFilePermissionFileTypeFileNameFileSizeReceivedBytesOldFileCreateTimeOldFileHashOldFileIDOldFileModificationTimeOldFileNameOldFilePathOldFilePermissionOldFileSizeOldFileTypeSentBytesRequestURLRequestClientApplicationRequestContextRequestCookiesRequestMethodSourceHostNameSourceMACAddressSourceNTDomainSourceDnsDomainSourceServiceNameSourceTranslatedAddressSourceTranslatedPortSourceProcessIdSourceUserPrivilegesSourceProcessNameSourceUserIDSourceUserNameEventTypeDeviceCustomIPv6Address1DeviceCustomIPv6Address1LabelDeviceCustomIPv6Address2DeviceCustomIPv6Address2LabelDeviceCustomIPv6Address3DeviceCustomIPv6Address3LabelDeviceCustomIPv6Address4DeviceCustomIPv6Address4LabelDeviceCustomFloatingPoint1DeviceCustomFloatingPoint1LabelDeviceCustomFloatingPoint2DeviceCustomFloatingPoint2LabelDeviceCustomFloatingPoint3DeviceCustomFloatingPoint3LabelDeviceCustomFloatingPoint4DeviceCustomFloatingPoint4LabelDeviceCustomNumber1DeviceCustomNumber1LabelDeviceCustomNumber2DeviceCustomNumber2LabelDeviceCustomNumber3DeviceCustomNumber3LabelDeviceCustomString1DeviceCustomString1LabelDeviceCustomString2DeviceCustomString2LabelDeviceCustomString3DeviceCustomString3LabelDeviceCustomString4DeviceCustomString4LabelDeviceCustomString5DeviceCustomString5LabelDeviceCustomString6DeviceCustomString6LabelDeviceCustomDate1DeviceCustomDate1LabelDeviceCustomDate2DeviceCustomDate2LabelFlexDate1FlexDate1LabelFlexNumber1FlexNumber1LabelFlexNumber2FlexNumber2LabelFlexString1FlexString1LabelFlexString2FlexString2LabelAdditionalExtensionsStartTimeEndTimeType_ResourceId
200000000-0000-0000-0000-000000000000OpsManager2020-02-06T09:26:24.94Z1580980000000Forcepoint CASBCloud Service Monitoring550224870638MonitorMonitorFALSEnull0.0.0.010.1.2.12my.skyfence.com//Unknown/Unknown/null52.9.67.149nullnullnull1AlertnullG Suite oneRSUnullFilesnullUserUnknownuser3@onersu.netnull00nullnullnullUnknown/Unknown/""Unmanagednullnullnullnullnullnullnullnullnullnulluser3@onersu.netFALSEnullnullDocument: Julia_visa-111.txt, ID: 1zzQHfGOolQKPl3BhkPxxcB6jqN2Cdgg1UNSHARE_ALLcat=/API-based Activitiesend=1580980527000outcome=Successreason=uploadstart=1580980527000AD.ThreatRadarCategory=AD.TORNetworks=AD.MaliciousIPs=AD.AnonymousProxies=AD.IPChain=AD.IPOrigin=UnknownAD.samAccountName=user1@onersu.netnullnullCommonSecurityLog
300000000-0000-0000-0000-000000000000OpsManager2020-02-06T10:24:59.467ZForcepoint CASBSaaS Security Gateway1046600000000BlockBlockTRUEnull40.90.137.12410.1.1.11my.skyfence.com//France/United StatesOffice Appsnullnullnullnull1ActivityOffice AppsnullOffice365nulla7d39ec98f8fe859a0802fd689c772f188e46072b8fd213e9b73625cbb563b85nullUseriqunghuigilh@mcrt.comnullnull-1nullnullnullhttps://login.live.com/rst...nullnullnullnullnullnullnullnullnullnullBlock Access to personal Office365nullnullcat=Normal Activityend=1580984363000outcome=Successreason=loginnullnullCommonSecurityLog
400000000-0000-0000-0000-000000000000OpsManager2020-02-06T09:16:27.053Z1573804384Forcepoint CASBCASB Admin audit log48783800000000000MonitorMonitorTRUEnull52.52.39.14610.1.1.11my.skyfence.com//United Kingdom/United StatesSkyfencenull127.255.255.255nullnullnull1ActivitySkyfencenullnull5c1e09157da8ec87c6d6a68f10c15bd8523c5d7ce2cfc03d48ebfa7568e4097fnullUserUnknownstodmin@irnet.com.comnullnull0nullnullnullhttps://my.skyfence.com/cm/j_spring_security_checkDesktop/Windows 10/"mozilla/5.0 (windows nt 10.0 win64 x64) applewebkit/537.36 (khtml, like gecko) chrome/78.0.3904.97 safari/537.36"Unmanagednullnullnullnullnullnullnullnullnullnullstodmin@irnet.com.comFALSEnullnullcat=Normal Activityend=1573804384outcome=Failurereason=loginstart=1573804384AD.ThreatRadarCategory=AD.TORNetworks=AD.MaliciousIPs=AD.AnonymousProxies=AD.IPChain=176.27.111.202AD.IPOrigin=External AD.samAnullnullCommonSecurityLog
500000000-0000-0000-0000-000000000000OpsManager2020-02-05T11:36:51.72ZForcepoint CASBSaaS Security Gateway4396640000008BlockBlockTRUEnull40.90.22.19110.1.1.11my.skyfence.com//Canada/United States/Office Appsnullnullnullnull1AlertOffice AppsnullOffice365nulla7d39ec98f8fe859a0802fd689c772f188e46072b8fd213e9b73625cbb563b85nullUseriqunghuigilh@mcrt.comnullnull0nullnullnullhttps://login.live.com/rst...nullnullnullnullnullnullnullnullnullnullnullnullcat=Client Locations/Not Allowed Client Locationsend=1576951001000outcome=Successreason=loginnullnullCommonSecurityLog