ASIM Authentication ASIM parser for Linux su

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index


Parser Information

Property Value
Parser Name ASimAuthenticationSu
Built-in Parser _ASim_Authentication_Su
Schema Authentication
Schema Version 0.1.3
Parser Type 🔌 Source (product-specific)
Product su
Parser Version 0.3.0 (version history)
Last Updated Jan 15, 2026
Unifying Parser ASimAuthentication
Source File Parsers\ASimAuthentication\Parsers\ASimAuthenticationSu.yaml

Description

This ASIM parser supports normalizing Linux su elevation commands collected using Syslog to the ASIM Authentication schema.

Source Tables

This parser reads from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
Syslog ProcessName == "su"
SyslogMessage has_all "pam_unix(su"
SyslogMessage startswith "FAILED SU"
SyslogMessage startswith "Successful su for"
?

Parameters

Name Type Default
disabled bool False

Associated Connectors

The following connectors provide data for this parser:

Connector Solution
SyslogAma Syslog

Solutions: Syslog

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index