How to map authentication story events? - Learn how to map authentication story events to the Cortex XSIAM Cortex Data Model. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2026-02-16
Category
Administrator Guide
Abstract

Learn how to map authentication story events to the Cortex XSIAM Cortex Data Model.

Cortex XSIAM enables analytics to run on all mapped authentication data, which automatically creates authentication stories for Cortex Data Model (XDM) identity data. As a result, you need to map authentication events to the Cortex XSIAM XDM schema to build the authentication story. For a complete list of these fields, see XDM fields for mapping authentication events.

Scope Clarification

This Feature focuses on authentication events related to SSO (Single Sign-On) and SaaS (Software-as-a-Service) application authentications. It does not cover internal authentication mechanisms such as Kerberos, NTLM, or traditional domain logon events generated by on-premise infrastructure.

Prerequisite

Familiarize yourself with the Cortex Data model (XDM) schema for field definitions and naming conventions, see Cortex XSIAM Data Model Schema.