Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel2
typeflat

Introduction

The tags beginning with endpoint.bitdefender identify events generated by Bitdefender

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed asendpoint.bitdefender. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

...

Technology

...

Brand

...

Type

...

Subtype

...

endpoint

...

bitdefender

agent

...

alert

...

detection

...

modify_value

...

network_connection

...

file_modify

...

log_out

...

log_on

...

rca_insight_event

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Bitdefender

endpoint.bitdefender.agent

endpoint.bitdefender.agent

endpoint.bitdefender.agent.active_host

endpoint.bitdefender.agent.active_host

endpoint.bitdefender.agent.alert

endpoint.bitdefender.agent.alert

endpoint.bitdefender.agent.connection_connect

endpoint.bitdefender.agent.connection_connect

endpoint.bitdefender.agent.ctc_raw_process_create

  • process_create

  • rca_insight

  • filescan_detection

  • terminate_process

  • file_delete

  • file_read

  • file_create

  • file_move

  • connection_connec

  • tinterface_change

  • user_logout

  • process_signa

  • linterface_added

  • process_create_fork

  • reg_delete_key

  • service_added

  • user_session_list

  • process_create_execve

  • user_account_settings_change

  • reg_delete_value

  • reg_modify_value

  • network_interfaces

  • gravityzone

    • product_modules_status

    These are the valid tags and corresponding data tables that will receive the parsers' data:

    Data table

    Tag

    endpoint.bitdefender.agent.ctc_raw_process_create

    endpoint.bitdefender.detection

    endpoint.bitdefender.detection

    endpoint.bitdefender.agent.external_notification_on_process

    endpoint.bitdefender.agent.external_notification_on_process

    endpoint.bitdefender.agent.alertfile_create

    endpoint.bitdefender.agent.alertfile_create

    endpoint.bitdefender.agent.detectionfile_delete

    endpoint.bitdefender.agent.detectionfile_delete

    endpoint.bitdefender.modify_value

    endpoint.bitdefender.modify_value

    endpoint.bitdefender.agent.networkfile_connectionmodify

    endpoint.bitdefender.agent.networkfile_connectionmodify

    endpoint.bitdefender.agent.file_modifymove

    endpoint.bitdefender.agent.file_modifymove

    endpoint.bitdefender.agent.logfile_outread

    endpoint.bitdefender.agent.logfile_outread

    endpoint.bitdefender.agent.logfilescan_ondetection

    endpoint.bitdefender.agent.logfilescan_ondetection

    endpoint.bitdefender.agent.rca_insight_eventgeneric_logging

    endpoint.bitdefender.agent.generic_logging

    endpoint.bitdefender.agent.rcainterface_insight_eventadded

    endpoint.bitdefender.agent.ctc_raw_process_createinterface_added

    endpoint.bitdefender.agent.ctc_raw_process_createinterface_change

    endpoint.bitdefender.agent.processinterface_createchange

    endpoint.bitdefender.agent.processlog_createon

    endpoint.bitdefender.agent.rcalog_insighton

    endpoint.bitdefender.agent.rcalog_insightout

    endpoint.bitdefender.agent.filescanlog_detectionout

    endpoint.bitdefender.agent.filescanlogon_detectionfailed

    endpoint.bitdefender.agent.terminatelogon_processfailed

    endpoint.bitdefender.agent.terminatenetwork_processconnection

    endpoint.bitdefender.agent.filenetwork_deleteconnection

    endpoint.bitdefender.agent.filenetwork_deleteinterfaces

    endpoint.bitdefender.agent.filenetwork_readinterfaces

    endpoint.bitdefender.agent.fileprocess_readcreate

    endpoint.bitdefender.agent.fileprocess_create

    endpoint.bitdefender.agent.fileprocess_create_execve

    endpoint.bitdefender.agent.fileprocess_create_moveexecve

    endpoint.bitdefender.agent.fileprocess_create_movefork

    endpoint.bitdefender.agent.connectionprocess_create_connectfork

    endpoint.bitdefender.agent.connectionprocess_connectsignal

    endpoint.bitdefender.agent.interfaceprocess_changesignal

    endpoint.bitdefender.agent.interfacerca_changeinsight

    endpoint.bitdefender.agent.userrca_logoutinsight

    endpoint.bitdefender.agent.userrca_insight_logoutevent

    endpoint.bitdefender.agent.processrca_insight_signalevent

    endpoint.bitdefender.agent.processreg_delete_signalkey

    endpoint.bitdefender.agent.interfacereg_delete_addedkey

    endpoint.bitdefender.agent.interfacereg_delete_addedvalue

    endpoint.bitdefender.agent.processreg_createdelete_forkvalue

    endpoint.bitdefender.agent.processreg_createmodify_forkvalue

    endpoint.bitdefender.agent.reg_deletemodify_keyvalue

    endpoint.bitdefender.agent.regscheduled_deletetask_keycreate

    endpoint.bitdefender.agent.servicescheduled_task_addedcreate

    endpoint.bitdefender.agent.service_added

    endpoint.bitdefender.agent.userservice_session_listadded

    endpoint.bitdefender.agent.userterminate_session_listprocess

    endpoint.bitdefender.agent.terminate_process_create_execve

    endpoint.bitdefender.agent.processuser_account_createsettings_execvechange

    endpoint.bitdefender.agent.user_account_settings_change

    endpoint.bitdefender.agent.user_account_settings_changelogout

    endpoint.bitdefender.agent.user_logout

    endpoint.bitdefender.agent.user_session_list

    endpoint.bitdefender.agent.reguser_deletesession_valuelist

    endpoint.bitdefender.agent.reguser_deletespecific_valuelogging

    endpoint.bitdefender.agent.reguser_modify_valuespecific_logging

    endpoint.bitdefender.agent.xrca

    endpoint.bitdefender.agent.xrca

    endpoint.bitdefender.agent.reg_modify_valuexrca_event

    endpoint.bitdefender.agent.xrca_event

    endpoint.bitdefender.agent.networkmodify_interfacesvalue

    endpoint.bitdefender.agent.networkmodify_interfacesvalue

    endpoint.bitdefender.gravityzone.product_modules_status

    endpoint.bitdefender.gravityzone.product_modules_status