Field in union table | Field in source table | Field transformation | Type | Extra fields |
---|
eventdate | eventdate | | timestamp
| |
source_event_date | at_timestamp winlog__event_data__UtcTime | Code Block |
---|
isnotnull(at_timestamp) ? at_timestamp : winlog__event_data__UtcTime |
| timestamp
| |
source | - | Code Block |
---|
"box.win_winlogbeat" |
| str
| |
keywords | - | | str
| |
event_type | winlog__keywords_first | | str
| |
channel | winlog__channel | | str
| |
category | winlog__task | | str
| |
event_id | winlog__event_id | | int4
| |
username | winlog__user__name winlog__event_data__User | Code Block |
---|
isnotnull(winlog__user__name) ? winlog__user__name : winlog__event_data__User |
| str
| |
security_id | winlog__event_data__SubjectUserSid winlog__event_data__TargetUserSid | Code Block |
---|
isnotnull(winlog__event_data__TargetUserSid) ? winlog__event_data__TargetUserSid : winlog__event_data__SubjectUserSid |
| str
| |
account | winlog__event_data__TargetUserName winlog__event_data__SubjectUserName | Code Block |
---|
isnotnull(winlog__event_data__TargetUserName) ? winlog__event_data__TargetUserName : winlog__event_data__SubjectUserName |
| str
| |
domain | winlog__user__domain | | str
| |
machine_ip | host__ip_first | Code Block |
---|
ip4(host__ip_first) |
| ip4
| |
subject_security_id | winlog__event_data__SubjectUserSid | | str
| |
subject_username | winlog__event_data__SubjectUserName | | str
| |
subject_domain | winlog__event_data__SubjectDomainName | | str
| |
subject_logon_id | winlog__event_data__SubjectLogonId | | str
| |
target_security_id | winlog__event_data__TargetUserSid | | str
| |
target_username | winlog__event_data__TargetUserName | | str
| |
target_domain | winlog__event_data__TargetDomainName | | str
| |
target_logon_id | winlog__event_data__TargetLogonId | | str
| |
target_object | winlog__event_data__TargetObject | | str
| |
target_image | - | | str
| |
member_security_id | - | | str
| |
member_name | winlog__event_data__MemberName | | str
| |
group_security_id | group__id | | str
| |
group_name | group__name | | str
| |
group_domain | group__domain | | str
| |
sam_account_name | winlog__event_data__SamAccountName | | str
| |
logon_type | winlog__event_data__LogonType | | str
| |
logon_guid | winlog__event_data__LogonGuid | | str
| |
logon_process | winlog__event_data__LogonProcessName | | str
| |
user_account_control | - | | str
| |
object_name | winlog__event_data__ObjectName | | str
| |
object_value_name | winlog__event_data__ObjectValueName | | str
| |
object_type | winlog__event_data__ObjectType | | str
| |
object_server | winlog__event_data__ObjectServer | | str
| |
object_handle | winlog__event_data__HandleId | | str
| |
object_resource_attribute | - | | str
| |
pid | winlog__event_data__CallerProcessId winlog__event_data__ProcessId | Code Block |
---|
isnotnull(winlog__event_data__ProcessId) ? winlog__event_data__ProcessId : winlog__event_data__CallerProcessId |
| str
| |
process_name | winlog__event_data__CallerProcessName winlog__event_data__ProcessName | Code Block |
---|
isnotnull(winlog__event_data__ProcessName) ? winlog__event_data__ProcessName : winlog__event_data__CallerProcessName |
| str
| |
process_guid | winlog__event_data__ProcessGuid | | str
| |
service | winlog__event_data__ServiceName | | str
| |
service_file_name | winlog__event_data__ServiceFileName winlog__event_data__ImagePath | Code Block |
---|
isnotnull(winlog__event_data__ServiceFileName) ? winlog__event_data__ServiceFileName : winlog__event_data__ImagePath |
| str
| |
service_account | winlog__event_data__ServiceAccount | | str
| |
machine | host__hostname | | str
| |
workstation | winlog__event_data__WorkstationName winlog__event_data__Workstation | Code Block |
---|
isnotnull(winlog__event_data__WorkstationName) ? winlog__event_data__WorkstationName : winlog__event_data__Workstation |
| str
| |
message | message | | str
| |
extended_message | - | | str
| |
source_name | winlog__provider_name | | str
| |
source_image | - | | str
| |
source_hostname | host__name | | str
| |
source_ip | winlog__event_data__IpAddress | | str
| |
source_port | winlog__event_data__IpPort | | str
| |
destination_hostname | - | | str
| |
destination_ip | winlog__event_data__DestIp | | str
| |
destination_port | winlog__event_data__DestPort | | str
| |
status | event__outcome | | str
| |
sub_status | winlog__event_data__sub_status | | str
| |
accesses | winlog__event_data__AccessList | | str
| |
access_mask | winlog__event_data__AccessMask | | str
| |
granted_access | - | | str
| |
properties | winlog__event_data__Properties | | str
| |
recovery_reason | - | | str
| |
token_elevation_type | winlog__event_data__TokenElevationType | | str
| |
mandatory_label | winlog__event_data__MandatoryLabel | | str
| |
caller_process_name | winlog__event_data__CallerProcessId winlog__event_data__ProcessId | Code Block |
---|
isnotnull(winlog__event_data__CallerProcessId) ? winlog__event_data__CallerProcessId : winlog__event_data__ProcessId |
| str
| |
caller_process_name | winlog__event_data__ProcessName winlog__event_data__CallerProcessName | Code Block |
---|
isnotnull(winlog__event_data__CallerProcessName) ? winlog__event_data__CallerProcessName : winlog__event_data__ProcessName |
| str
| |
new_pid | winlog__event_data__NewProcessId | | str
| |
new_process_name | winlog__event_data__NewProcessName | | str
| |
parent_pid | winlog__event_data__ParentProcessId | | str
| |
parent_process_name | process__parent__name | | str
| |
parent_process_guid | winlog__event_data__ParentProcessGuid | | str
| |
parent_command_line | winlog__event_data__ParentCommandLine | | str
| |
process_command_line | process__command_line | | str
| |
file_path | - | | str
| |
file_version | winlog__event_data__FileVersion | | str
| |
original_file_name | winlog__event_data__OriginalFileName | | str
| |
current_directory | winlog__event_data__CurrentDirectory | | str
| |
integrity_level | winlog__event_data__IntegrityLevel | | str
| |
hashes | winlog__event_data__Hashes | | str
| |
company | winlog__event_data__Company | | str
| |
product | winlog__event_data__Product | | str
| |
description | winlog__event_data__Description | | str
| |
import_hash | - | | str
| |
start_module | - | | str
| |
start_function | - | | str
| |
computer_name | winlog__computer_name | | str
| |
device | - | | str
| |
pipe_name | - | | str
| |
query_name | winlog__event_data__QueryName | | str
| |
query_status | winlog__event_data__QueryStatus | | str
| |
query_results | winlog__event_data__QueryResults | | str
| |
share_name | winlog__event_data__ShareName | | str
| |
share_local_path | winlog__event_data__ShareLocalPath | | str
| |
relative_target_name | winlog__event_data__RelativeTargetName | | str
| |
class_id | winlog__event_data__ClassId | | str
| |
class_name | winlog__event_data__ClassName | | str
| |
device_id | winlog__event_data__DeviceId | | str
| |
device_name | winlog__event_data__DeviceDescription | | str
| |
task_name | winlog__event_data__TaskName | | str
| |
task_content | winlog__event_data__TaskContent | | str
| |
ticket_options | winlog__event_data__TicketOptions | | str
| |
ticket_encryption_type | winlog__event_data__TicketEncryptionType | | str
| |
signature | winlog__event_data__Signature | | str
| |
initiated | winlog__event_data__Initiated | | str
| |
key_length | winlog__event_data__KeyLength | Code Block |
---|
int8(winlog__event_data__KeyLength) |
| int8
| |
reason | winlog__event_data__FailureReason winlog__event_data__AccessReason | Code Block |
---|
isnull(winlog__event_data__FailureReason) ? winlog__event_data__AccessReason : winlog__event_data__FailureReason |
| str
| |
image | winlog__event_data__Image | | str
| |
parent_image | winlog__event_data__ParentImage | | str
| |
context_info | winlog__event_data__ContextInfo | | str
| |
engine_version | message__engineVersion | | str
| |
host_version | message__hostVersion | | str
| |
payload | winlog__event_data__Payload | | str
| |
layer_rtid | winlog__event_data__LayerRTID | | str
| |
authentication_package_name | winlog__event_data__AuthenticationPackageName | | str
| |
new_value | winlog__event_data__NewValue | | str
| |
privilege_list | winlog__event_data__PrivilegeList | | str
| |
attribute_value | winlog__event_data__AttributeValue | | str
| |
attribute_ldap_display_name | winlog__event_data__AttributeLDAPDisplayName | | str
| |
audit_policy_changes | winlog__event_data__AuditPolicyChanges | | str
| |
power_shell_script_block_id | - | | str
| |
operation_type | winlog__event_data__OperationType | | str
| |
hostchain | hostchain | | str
| ✓ |
tag | tag | | str
| ✓ |
rawMessage | rawMessage | | str
| ✓ |