FortiSIEM Discussions
HugoPinto
Contributor

O365 Parser

Hi,

we share with this forum an adapted parser for O365 collect Rule creation, and other stuff. 

New custom event attributes:

moveToFolder
InboxRuleName
stopProcessingRules
markAsRead
subjectContainsWords
deletedItem

Cheers

Hugo Pinto
Claranet Portugal
1 REPLY 1
AdonisSardinas

KUDOS!!!!!

------------------------------
?‍? Adonis Sardinas
? Systems Engineer - Latin America & Caribbean
?Certified: NSE 4, Fast Track Trainer, CISSP, CEH, CNDA, CCNA Cyber

☎ Tech Support: 1-866-648-4638 (us toll free)
More Support numbers: ? http://www.fortinet.com/support/contact_support.html

?https://www.fortinet.com/support/contact_support.html
?https://support.fortinet.com
?https://docs.fortinet.com
?https://kb.fortinet.com
------------------------------
-------------------------------------------
Original Message:
Sent: Jul 30, 2020 01:42 AM
From: Hugo Pinto
Subject: O365 Parser

Hi,

we share with this forum an adapted parser for O365 collect Rule creation, and other stuff. 

New custom event attributes:

moveToFolder
InboxRuleName
stopProcessingRules
markAsRead
subjectContainsWords
deletedItem

Cheers

Hugo Pinto
Claranet Portugal