Event Categorization
In this new version, events are categorized in a more granular method so as to provide the most useful information to QRadar.
QRadar groups events based on the
EventID
and
cat
fields. Lookout Mobile Risk API events come in three high level categories THREAT, DEVICE, and AUDIT. Each of these categories uses a different method to populate the
EventID
and
cat
fields. Please see the following tables for explanations of how the
cat
field is populated for each event type.