Cloud SIEM Record Types
Each message that Cloud SIEM maps must be assigned one, and only one, record type. For the complete list of record types, see Schema: Record Types in the Cloud SIEM Content Catalog.
Note that it is possible for multiple mappers to match a particular log message and each create a unique record for that message—those multiple records can have different record types. It isn’t standard practice to create multiple Cloud SIEM records from a single log message, but it is possible if there is a use case. For related information, see Attributes You Can Map to Records.