ASIM Audit event ASIM filtering parser.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index


Parser Information

Property Value
Parser Name imAuditEvent
Built-in Parser _Im_AuditEvent
Schema AuditEvent
Schema Version 0.1
Parser Type 📦 Union (schema-level)
Parser Version 0.1.6 (version history)
Last Updated March 10, 2026
Source File Parsers\ASimAuditEvent\Parsers\imAuditEvent.yaml

Description

This ASIM parser supports normalizing audit events from all supported sources to the ASIM Audit Event activity normalized schema. This is an similar to to the ASIM version, but using different exclusion keys.

Products

This union parser includes parsers for the following products:

Product Source Parser Solutions
AWS CloudTrail _Im_AuditEvent_AWSCloudTrail Amazon Web Services
Microsoft Azure _Im_AuditEvent_AzureActivity Azure Activity
Azure Key Vault _Im_AuditEvent_AzureKeyVault
Barracuda WAF _Im_AuditEvent_BarracudaCEF Common Event Format
VirtualMetric DataStream
Zscaler Internet Access
Barracuda WAF _Im_AuditEvent_BarracudaWAF
Cisco ISE _Im_AuditEvent_CiscoISE Syslog
Cisco Meraki _Im_AuditEvent_CiscoMeraki CiscoMeraki
CustomLogsAma
Cisco Meraki _Im_AuditEvent_CiscoMerakiSyslog Syslog
CrowdStrike Falcon Endpoint Protection _Im_AuditEvent_CrowdStrikeFalconHost Common Event Format
VirtualMetric DataStream
Zscaler Internet Access
Illumio Core _Im_AuditEvent_IllumioSaaSCore IllumioSaaS
Infoblox BloxOne _Im_AuditEvent_InfobloxBloxOne Common Event Format
VirtualMetric DataStream
Zscaler Internet Access
Microsoft Windows _Im_AuditEvent_MicrosoftEvent
Microsoft SharePoint _Im_AuditEvent_MicrosoftExchangeAdmin365
Microsoft Windows _Im_AuditEvent_MicrosoftSecurityEvents Windows Security Events
Microsoft Windows _Im_AuditEvent_MicrosoftWindowsEvents Windows Forwarded Events
Native _Im_AuditEvent_Native Cisco Meraki Events via REST API
SynqlyIntegrationConnector
Workday
SQLSecurityAudit Logs _Im_AuditEvent_SQLSecurityAudit
SentinelOne _Im_AuditEvent_SentinelOne
VMware Carbon Black Cloud _Im_AuditEvent_VMwareCarbonBlackCloud
Vectra _Im_AuditEvent_VectraXDRAudit Vectra XDR

Parameters

Name Type Default
starttime datetime datetime(null)
endtime datetime datetime(null)
srcipaddr_has_any_prefix dynamic dynamic([])
actorusername_has_any dynamic dynamic([])
operation_has_any dynamic dynamic([])
eventtype_in dynamic dynamic([])
eventresult string *
object_has_any dynamic dynamic([])
newvalue_has_any dynamic dynamic([])
pack bool False

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index