Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

These are the fields displayed in these tables:

  • dlp.digitalguardian.arc.events

  • dlp.digitalguardian.endpointdlp.alerts

  • dlp.digitalguardian.endpointdlp.audit

  • dlp.digitalguardian.endpointdlp.classification

  • dlp.digitalguardian.endpointdlp.events

  • dlp.digitalguardian.endpointdlp

  • dlp.digitalguardian.networkdlp.events

  • dlp.digitalguardian.networkdlp.system

  • dlp.digitalguardian.networkdlp

dlp.digitalguardian.arc.events

Field

Type

Extra field

eventdate

timestamp

hostname

str

machine_type

str

file_internal_name

str

application

str

md5_hash

str

original_name

str

dg_custom_data_dg_scope

str

parent_application

str

process_directory

str

was_rule_violated

str

process_local_creation_time

str

process_path

str

process_file_extension

str

was_removable

str

dg_custom_data_dg_values

str

is_user_local_admin

str

event_display_name

str

dg_custom_data_dg_name

str

company_name

str

file_version

str

product_name

str

user_domain

str

mac_address

str

user

str

agent_version

str

unique_id

str

command_line

str

product_version

str

computer_name

str

application_internal_name

str

was_mobile_device

str

_time

timestamp

operation_type

str

process_file_size

str

was_detail_blocked

str

process_domain

str

event_local_time

str

was_classified

str

file_description

str

parent_md5_hash

str

sha256_hash

str

process_pid

int4

server_process_time

timestamp

event_time

str

parent_process_internal_name

str

process_local_modify_time

str

x86_or_x64

str

process_local_access_time

str

is_virtual_session

str

bytes_written

str

destination_drive_type

str

dg_src_dev_dev_prdname

str

source_was_classified

str

destination_file_extension

str

destination_file_name

str

attachment_file_size

str

dg_dst_dev_dev_bt

str

attachment_source_file_name

str

destination_was_classified

str

source_file_extension

str

dg_dst_dev_dev_dt

str

dg_src_dev_dev_dt

str

attachment_source_file_path

str

destination_file_encryption

str

dg_dst_dev_dev_vendor

str

dg_src_dev_dev_bt

str

dg_dst_dev_dev_prdname

str

dg_src_dev_dev_vendor

str

destination_bus_type

str

attachment_source_directory

str

attachment_source_drive_type

str

source_is_removable

str

source_file_encryption

str

destination_file_path

str

destination_is_removable

str

destination_directory

str

bytes_read

str

dns_hostname

str

url_path

str

dg_alert_dg_policy_dg_category_name

str

was_private_address

str

dg_alert_dg_category_name

str

network_direction

str

source_ip_address

str

dg_alert_alert_etu

str

wireless_ssid

str

remote_port

str

dg_alert_dg_rule_action_type

str

dg_alert_alert_ur

str

adapter_name

str

dg_alert_dg_name

str

was_wireless

str

local_port

str

dg_alert_alert_at

str

dg_alert_alert_al

str

protocol

str

dg_alert_alert_wb

str

dg_alert_alert_etl

str

dg_alert_dg_policy_dg_name

str

dg_alert_dg_detection_source

str

encryption_status

str

dg_alert_alert_bc

str

ip_address

str

was_mobile_copy

str

dg_recipients_uad_mr

str

dg_attachments_dg_src_dir

str

dg_attachments_dg_file_size

str

event_was_blocked

str

event_has_rule_violation

str

dg_recipients_uad_mrt

str

dg_attachments_uad_sdt

str

email_subject

str

dg_attachments_uad_sp

str

email_sender

str

dg_attachments_dg_src_file_name

str

dg_recipients_dg_rec_email_domain

str

url_host

str

url_context_path

str

url_port

int4

url_scheme

str

hostchain

str

tag

str

rawMessage

str

...