How to map authentication events for analytics
Map authentication events for Cortex XSIAM analytics.
Cortex XSIAM enables analytics to run on all mapped authentication data, which automatically creates authentication stories for Cortex Data Model (XDM) identity data. To build these stories, you must map authentication events to the XDM schema using specific mandatory fields and principles. For a complete list of these fields, see XDM fields for mapping authentication events.
Prerequisite
You must have View/Edit RBAC permissions for Data Management (under Configurations > Data Management).
Familiarize yourself with the Cortex Data model (XDM) schema for field definitions and naming conventions, see XSIAM Data Model Schema.
Scope Clarification
This Feature focuses on authentication events related to SSO (Single Sign-On) and SaaS (Software-as-a-Service) application authentications. It does not cover internal authentication mechanisms such as Kerberos, NTLM, or traditional domain logon events generated by on-premise infrastructure.
Last updated
Was this helpful?
