Skip to main content

Threat Intelligence Mapping

Global feed mapping​

Sumo Logic provides an out-of-the-box a _sumo_global_feed_cs source of threat intelligence indicators supplied by Sumo Logic. You can see it in the Threat Intelligence tab. This source is a default source and cannot be changed or deleted.

In the threat intelligence datastore, the schema is mapped to normalized values to provide ease of interoperability with the schema from other threat intelligence sources:

Original schemaNormalized schema in the datastore
actoractors
idid
indicatorindicator
kill_chain_phaseskillChain
labels.ThreatTypethreatType
last_updatedupdated
malicious_confidenceconfidence (normalized to the 0-100 scale)
published_datevalidFrom and imported
typetype

(All other fields will be kept in the fields{} object.)

The type object is mapped to the following normalized type values:

TypeNormalized type in the datastore
binary_stringartifact:payload_bin
bitcoin_addressurl
ip_addressipv4-addr / ipv6-addr
domaindomain-name
email_addressemail-add
file_pathfile:name
file_namefile:name
hash_md5file:hashes.'MD5'
hash_sha1file:hashes.'SHA-1'
hash_sha256file:hashes.'SHA-256'
mutex_namemutex:name
service_nameprocess:name
urlurl
usernameuser-account:user_id
user_agenthttp-request-ext:request_header.'User-Agent'
x509_subjectx509-certificate:serial_number
Status
Legal
Privacy Statement
Terms of Use

Copyright © 2025 by Sumo Logic, Inc.