As stated in the title, I'm looking for someone tell the differences between the field user and srcuser in the CIM Model Change Analysis (AllChange.Account_Management). The definitions in Splunk document are not clear enough.
For example, when the user userA reset the password for user userB, I can see the following message in the logs
2016-05-24, 11:25:33.001, Account, "Password Reset", "[Dummy-0] [user:userA ip:10.1.1.1 group:admin] Update the password of user userB."
In this case, for userA, shall I map it to field srcuser or field user? For user_B account shall I map it to CIM field "user" or field "object"?
I'd put userA into the user field, and userB into the object field. The user is performing the change, the object is being changed.
You can use src_user if you have two accounts being used. For example if you see changes made to a database, if your data contains both the account used to log in to the database as well as the account used to log in to the operating system you'd put the database account into user and the operating system account into src_user. If you have a remote log in to some account and also know the account used on the src from where the remote log in originated, that's again the src_user while the account used on the remote system would be the user.