XDM fields for mapping authentication events - Learn more about the Cortex Data Model (XDM) fields to map for authentication events. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2026-03-03
Category
Administrator Guide
Abstract

Learn more about the Cortex Data Model (XDM) fields to map for authentication events.

This section provides a comprehensive guide to mapping authentication events from various customer log sources to the XDM (Cortex Data Model) schema. Each relevant XDM field is detailed, including whether the field is mandatory or optional, the corresponding "Authentication Story" field , data type, and purpose, ensuring consistent data normalization essential for robust security analysis and threat detection.

The fields that are mandatory to map are listed below with an asterisk (*) beside them as these fields must be mapped to automatically create authentication stories for XDM identity data.

Note

For more information on the entire Cortex Data model (XDM) schema, see Cortex XSIAM Data Model Schema.