...
These are the fields displayed in these tables:
uba.exabeam.notables
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
timestamp |
| |
id |
| |
score |
| |
user |
| |
src_ip |
| |
dest_ip |
| |
event_time |
| |
event_type |
| |
host |
| |
rawlog_time |
| |
time |
| |
source |
| |
vendor |
| |
lockout_id |
| |
session_id |
| |
isp |
| |
country_code |
| |
session_order |
| |
account |
| |
failure_reason |
| |
rule_id |
| |
rule_name |
| |
rule_description |
| |
rule_reason |
| |
src_host |
| |
rawlog_refs |
| |
alert_name |
| |
local_asset |
| |
outcome |
| |
alert_type |
| |
additional_info |
| |
alert_id |
| |
alert_severity |
| |
url |
| |
start_time |
| |
end_time |
| |
status |
| |
accounts |
| |
labels |
| |
assets |
| |
zones |
| |
top_reasons |
| |
reasons_count |
| |
events_count |
| |
alerts_count |
| |
sequence_type |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
...