Table of Contents | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
|
Introduction
The tags begin with edr.cortex_xdr
identify the events generated by Cortex XDR.
Tag structure
The full tag must have 3 levels. The first two are fixed as edr.cortex_xdr
. The third level identifies the type of events sent.
Product / Services | Tags | Data tables |
---|---|---|
Cortex XDR |
|
|
|
| |
|
| |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
incident_id |
|
|
alert__external_id |
|
|
alert__severity |
|
|
alert__matching_status |
|
|
alert__end_match_attempt_ts |
|
|
alert__local_insert_ts |
|
|
alert__bioc_indicator |
|
|
alert__matching_service_rule_id |
|
|
alert__attempt_counter |
|
|
alert__bioc_category_enum_key |
|
|
alert__case_id |
|
|
alert__is_whitelisted |
|
|
alert__starred |
|
|
alert__deduplicate_tokens |
|
|
alert__filter_rule_id |
|
|
alert__mitre_technique_id_and_name |
|
|
alert__mitre_tactic_id_and_name |
|
|
alert__agent_version |
|
|
alert__agent_device_domain |
|
|
alert__agent_fqdn |
|
|
alert__agent_os_type |
|
|
alert__agent_os_sub_type |
|
|
alert__agent_data_collection_status |
|
|
alert__mac |
|
|
alert__agent_is_vdi |
|
|
alert__agent_install_type |
|
|
alert__agent_host_boot_time |
|
|
alert__event_sub_type |
|
|
alert__module_id |
|
|
alert__association_strength |
|
|
alert__dst_association_strength |
|
|
alert__story_id |
|
|
alert__event_id |
|
|
alert__event_type |
|
|
alert__event_timestamp |
|
|
alert__actor_process_instance_id |
|
|
alert__actor_process_image_path |
|
|
alert__actor_process_image_name |
|
|
alert__actor_process_command_line |
|
|
alert__actor_process_signature_status |
|
|
alert__actor_process_signature_vendor |
|
|
alert__actor_process_image_sha256 |
|
|
alert__actor_process_image_md5 |
|
|
alert__actor_process_causality_id |
|
|
alert__actor_causality_id |
|
|
alert__actor_process_os_pid |
|
|
alert__actor_thread_thread_id |
|
|
alert__causality_actor_process_image_name |
|
|
alert__causality_actor_process_command_line |
|
|
alert__causality_actor_process_image_path |
|
|
alert__causality_actor_process_signature_vendor |
|
|
alert__causality_actor_process_signature_status |
|
|
alert__causality_actor_causality_id |
|
|
alert__causality_actor_process_execution_time |
|
|
alert__causality_actor_process_image_md5 |
|
|
alert__causality_actor_process_image_sha256 |
|
|
alert__action_file_path |
|
|
alert__action_file_name |
|
|
alert__action_file_md5 |
|
|
alert__action_file_sha256 |
|
|
alert__action_file_macro_sha256 |
|
|
alert__action_registry_data |
|
|
alert__action_registry_key_name |
|
|
alert__action_registry_value_name |
|
|
alert__action_registry_full_key |
|
|
alert__action_local_ip |
|
|
alert__action_local_port |
|
|
alert__action_remote_ip |
|
|
alert__action_remote_port |
|
|
alert__action_external_hostname |
|
|
alert__action_country |
|
|
alert__action_process_instance_id |
|
|
alert__action_process_causality_id |
|
|
alert__action_process_image_name |
|
|
alert__action_process_image_sha256 |
|
|
alert__action_process_image_command_line |
|
|
alert__action_process_signature_status |
|
|
alert__action_process_signature_vendor |
|
|
alert__os_actor_effective_username |
|
|
alert__os_actor_process_instance_id |
|
|
alert__os_actor_process_image_path |
|
|
alert__os_actor_process_image_name |
|
|
alert__os_actor_process_command_line |
|
|
alert__os_actor_process_signature_status |
|
|
alert__os_actor_process_signature_vendor |
|
|
alert__os_actor_process_image_sha256 |
|
|
alert__os_actor_process_causality_id |
|
|
alert__os_actor_causality_id |
|
|
alert__os_actor_process_os_pid |
|
|
alert__os_actor_thread_thread_id |
|
|
alert__fw_app_id |
|
|
alert__fw_interface_from |
|
|
alert__fw_interface_to |
|
|
alert__fw_rule |
|
|
alert__fw_rule_id |
|
|
alert__fw_device_name |
|
|
alert__fw_serial_number |
|
|
alert__fw_url_domain |
|
|
alert__fw_email_subject |
|
|
alert__fw_email_sender |
|
|
alert__fw_email_recipient |
|
|
alert__fw_app_subcategory |
|
|
alert__fw_app_category |
|
|
alert__fw_app_technology |
|
|
alert__fw_vsys |
|
|
alert__fw_xff |
|
|
alert__fw_misc |
|
|
alert__fw_is_phishing |
|
|
alert__dst_agent_id |
|
|
alert__dst_causality_actor_process_execution_time |
|
|
alert__dns_query_name |
|
|
alert__dst_action_external_hostname |
|
|
alert__dst_action_country |
|
|
alert__dst_action_external_port |
|
|
alert__contains_featured_host |
|
|
alert__contains_featured_user |
|
|
alert__contains_featured_ip |
|
|
alert__image_name |
|
|
alert__container_id |
|
|
alert__cluster_name |
|
|
alert__referenced_resource |
|
|
alert__operation_name |
|
|
alert__identity_sub_type |
|
|
alert__identity_type |
|
|
alert__project |
|
|
alert__cloud_provider |
|
|
alert__resource_type |
|
|
alert__resource_sub_type |
|
|
alert__user_agent |
|
|
alert__events_length |
|
|
alert__alert_id |
|
|
alert__detection_timestamp |
|
|
alert__name |
|
|
alert__category |
|
|
alert__endpoint_id |
|
|
alert__description |
|
|
alert__host_ip |
|
|
alert__host_name |
|
|
alert__source |
|
|
alert__action |
|
|
alert__action_pretty |
|
|
alert__user_name |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
external_id |
|
|
| |||
severity |
|
|
| |||
matching_status |
|
|
| |||
end_match_attempt_ts |
|
|
| |||
local_insert_ts |
|
|
| |||
last_modified_ts |
|
|
| |||
bioc_indicator |
|
|
| |||
matching_service_rule_id |
|
|
| |||
attempt_counter |
|
|
| |||
bioc_category_enum_key |
|
|
| |||
is_whitelisted |
|
|
| |||
starred |
|
|
| |||
deduplicate_tokens |
|
|
| |||
filter_rule_id |
|
|
| |||
mitre_technique_id_and_name_str |
|
| mitre_technique_id_and_name | |||
mitre_tactic_id_and_name_str |
|
| mitre_tactic_id_and_name | |||
agent_version |
|
|
| |||
agent_ip_addresses_v6 |
|
|
| |||
agent_device_domain |
|
|
| |||
agent_fqdn |
|
|
| |||
agent_os_type |
|
|
| |||
agent_os_sub_type |
|
|
| |||
agent_data_collection_status |
|
|
| |||
mac |
|
|
| |||
is_pcap |
|
|
| |||
alert_type |
|
|
| |||
resolution_status |
|
|
| |||
resolution_comment |
|
|
| |||
dynamic_fields |
|
|
| |||
alert_id |
|
|
| |||
detection_timestamp |
|
|
| |||
name |
|
|
| |||
category |
|
|
| |||
endpoint_id |
|
|
| |||
description |
|
|
| |||
host_ip_str |
|
| host_ip | |||
host_name |
|
|
| |||
mac_addresses |
|
|
| |||
source |
|
|
| |||
action |
|
|
| |||
action_pretty |
|
|
| |||
tags_str |
|
| tags | |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
external_id |
|
|
agent_install_type |
|
|
agent_host_boot_time |
|
|
event_sub_type |
|
|
module_id |
|
|
association_strength |
|
|
dst_association_strength |
|
|
story_id |
|
|
event_id |
|
|
event_type |
|
|
event_timestamp |
|
|
actor_process_instance_id |
|
|
actor_process_image_path |
|
|
actor_process_image_name |
|
|
actor_process_command_line |
|
|
actor_process_signature_status |
|
|
actor_process_signature_vendor |
|
|
actor_process_image_sha256 |
|
|
actor_process_image_md5 |
|
|
actor_process_causality_id |
|
|
actor_causality_id |
|
|
actor_process_os_pid |
|
|
actor_thread_thread_id |
|
|
causality_actor_process_image_name |
|
|
causality_actor_process_command_line |
|
|
causality_actor_process_image_path |
|
|
causality_actor_process_signature_vendor |
|
|
causality_actor_process_signature_status |
|
|
causality_actor_causality_id |
|
|
causality_actor_process_execution_time |
|
|
causality_actor_process_image_md5 |
|
|
causality_actor_process_image_sha256 |
|
|
action_file_path |
|
|
action_file_name |
|
|
action_file_md5 |
|
|
action_file_sha256 |
|
|
action_file_macro_sha256 |
|
|
action_registry_data |
|
|
action_registry_key_name |
|
|
action_registry_value_name |
|
|
action_registry_full_key |
|
|
action_local_ip |
|
|
action_local_ip_v6 |
|
|
action_local_port |
|
|
action_remote_ip |
|
|
action_remote_ip_v6 |
|
|
action_remote_port |
|
|
action_external_hostname |
|
|
action_country |
|
|
action_process_instance_id |
|
|
action_process_causality_id |
|
|
action_process_image_name |
|
|
action_process_image_sha256 |
|
|
action_process_image_command_line |
|
|
action_process_signature_status |
|
|
action_process_signature_vendor |
|
|
os_actor_effective_username |
|
|
os_actor_process_instance_id |
|
|
os_actor_process_image_path |
|
|
os_actor_process_image_name |
|
|
os_actor_process_command_line |
|
|
os_actor_process_signature_status |
|
|
os_actor_process_signature_vendor |
|
|
os_actor_process_image_sha256 |
|
|
os_actor_process_causality_id |
|
|
os_actor_causality_id |
|
|
os_actor_process_os_pid |
|
|
os_actor_thread_thread_id |
|
|
fw_app_id |
|
|
fw_interface_from |
|
|
fw_interface_to |
|
|
fw_rule |
|
|
fw_rule_id |
|
|
fw_device_name |
|
|
fw_serial_number |
|
|
fw_url_domain |
|
|
fw_email_subject |
|
|
fw_email_sender |
|
|
fw_email_recipient |
|
|
fw_app_subcategory |
|
|
fw_app_category |
|
|
fw_app_technology |
|
|
fw_vsys |
|
|
fw_xff |
|
|
fw_misc |
|
|
fw_is_phishing |
|
|
dst_agent_id |
|
|
dst_causality_actor_process_execution_time |
|
|
dns_query_name |
|
|
dst_action_external_hostname |
|
|
dst_action_country |
|
|
dst_action_external_port |
|
|
contains_featured_host |
|
|
contains_featured_user |
|
|
contains_featured_ip |
|
|
image_name |
|
|
container_id |
|
|
cluster_name |
|
|
referenced_resource |
|
|
operation_name |
|
|
identity_sub_type |
|
|
identity_type |
|
|
project |
|
|
cloud_provider |
|
|
resource_type |
|
|
resource_sub_type |
|
|
user_agent |
|
|
username |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
hostname |
|
| |
incident_id |
|
| |
incident_name |
|
| |
creation_time |
|
| |
modification_time |
|
| |
detection_time |
|
| |
status |
|
| |
severity |
|
| |
description |
|
| |
assigned_user_mail |
|
| |
assigned_user_pretty_name |
|
| |
alert_count |
|
| |
low_severity_alert_count |
|
| |
med_severity_alert_count |
|
| |
high_severity_alert_count |
|
| |
user_count |
|
| |
host_count |
|
| |
notes |
|
| |
resolve_comment |
|
| |
resolved_timestamp |
|
| |
manual_severity |
|
| |
manual_description |
|
| |
xdr_url |
|
| |
starred |
|
| |
hosts_str |
| hosts | |
users_str |
| users | |
incident_sources_str |
| incident_sources | |
rule_based_score |
|
| |
manual_score |
|
| |
wildfire_hits |
|
| |
alerts_grouping_status |
|
| |
mitre_tactics_ids_and_names |
|
| |
mitre_techniques_ids_and_names |
|
| |
alert_categories |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |