Commvault to CrowdStrike field mapping for the following event codes are shown below.
| Feature | Type | Event Codes |
|---|---|---|
| Threat Scan | Malware Detection | 69:59, 17:193 |
| Threat Scan | Encryption detection | 69:60 |
| Threat Scan | Anomaly Detection | 14:337, 14:338, 7:349 |
| Risk Analysis | Sensitive data detection | 35:5636 |
Field Mapping for Event Code 35:5636
| Sr. No. | Commvault | CrowdStrike | Mandatory (Y/N) |
|---|---|---|---|
| 1 | Alert | Vendor.alert | |
| 2 | Type | Vendor.type | |
| 3 | Detected Time | Vendor.detected_time | |
| 4 | Time zone | Vendor.time_zone, @timezone | |
| 5 | CommCell | Vendor.commcell | |
| 6 | Alert Rule Name | Vendor.alert_rule_name | |
| 7 | Project | Vendor.project | |
| 8 | Description | Vendor.description | |
| 9 | critical (from Description) | Vendor.critical | |
| 10 | high (from Description) | Vendor.high | |
| 11 | moderate (from Description) | Vendor.moderate | |
| 12 | data source | Vendor.hostname | |
| 13 | project | Vendor.project | |
| 14 | Event Code | Vendor.event_code | Y |
| 15 | Condition Cleared | Vendor.condition_cleared | |
| 16 | event.category[0] | Y | |
| 17 | event.type[0] | Y |
Field Mapping for Event Code 69:59 and Event Code 17:193
| Sr. No. | Commvault | CrowdStrike | Mandatory (Y/N) |
|---|---|---|---|
| 1 | Alert | Vendor.alert | |
| 2 | Type | Vendor.type | |
| 3 | Detected Time | Vendor.detected_time | |
| 4 | Time zone | Vendor.time_zone, @timezone | |
| 5 | CommCell | Vendor.commcell | |
| 6 | Alert Rule Name | Vendor.alert_rule_name | |
| 7 | Client | Vendor.hostname | |
| 8 | Description | Vendor.description | |
| 9 | client (from Description) | Vendor.hostname | |
| 10 | count (from Description) | Vendor.threats | |
| 11 | Time | Vendor.detected_time | |
| 12 | Event Code | Vendor.event_code | Y |
| 13 | Condition Cleared | Vendor.condition_cleared | |
| 14 | event.category[0] | Y | |
| 15 | event.type[0] | Y |
Field Mapping for Event Code 69:60
| Sr. No. | Commvault | CrowdStrike | Mandatory (Y/N) |
|---|---|---|---|
| 1 | Alert | Vendor.alert | |
| 2 | Type | Vendor.type | |
| 3 | Detected Time | Vendor.detected_time | |
| 4 | Time zone | Vendor.time_zone, @timezone | |
| 5 | CommCell | Vendor.commcell | |
| 6 | Alert Rule Name | Vendor.alert_rule_name | |
| 7 | Client | Vendor.hostname | |
| 8 | Description | Vendor.description | |
| 9 | client (from Description) | Vendor.hostname | |
| 10 | count (from Description) | Vendor.threats | |
| 11 | Time | Vendor.detected_time | |
| 12 | Event Code | Vendor.event_code | Y |
| 13 | Condition Cleared | Vendor.condition_cleared | |
| 14 | event.category[0] | Y | |
| 15 | event.type[0] | Y |
Field Mapping for Event Code 14:338, Event Code 14:337, and Event Code 7:349
| Sr. No. | Commvault | CrowdStrike | Mandatory (Y/N) |
|---|---|---|---|
| 1 | Alert | Vendor.alert | |
| 2 | Type | Vendor.type | |
| 3 | Detected | TimeVendor.detected_time | |
| 4 | Time zone | Vendor.time_zone, @timezone | |
| 5 | CommCell | Vendor.commcell | |
| 6 | Alert Rule Name | Vendor.alert_rule_name | |
| 7 | Client | Vendor.hostname | |
| 8 | Description | Vendor.description | |
| 9 | job (from Description) | Vendor.backup_job_id | |
| 10 | client (from Description) | Vendor.hostname | |
| 11 | number of added files (from Description) | Vendor.anomaly_[0] | |
| 12 | number of deleted files (from Description) | Vendor.anomaly_[1] | |
| 13 | Time | Vendor.detected_time | |
| 14 | Event Code | Vendor.event_code | Y |
| 15 | Condition Cleared | Vendor.condition_cleared | |
| 16 | event.category[0] | Y | |
| 17 | event.type[0] | Y |