Field | Type | Field transformation | Source field name | Extra fields |
---|
eventdate | timestamp
| | | |
hostname | str
| | | |
id | str
| | | |
incidentId | int8
| | | |
investigationId | int8
| | | |
assignedTo | str
| | | |
severity | str
| | | |
status | str
| | | |
classification | str
| | | |
determination | str
| | | |
investigationState | str
| | | |
detectionSource | str
| | | |
detectorId | str
| | | |
category | str
| | | |
threatFamilyName | str
| | | |
title | str
| | | |
description | str
| | | |
alertCreationTime | str
| | | |
firstEventTime | str
| | | |
lastEventTime | str
| | | |
lastUpdateTime | str
| | | |
resolvedTime | str
| | | |
machineId | str
| | | |
computerDnsName | str
| | | |
rbacGroupName | str
| | | |
aadTenantId | str
| | | |
threatName | str
| | | |
mitreTechniques_str | str
| Code Block |
---|
join(mitreTechniques, ',') |
| mitreTechniques | |
relatedUser__userName | str
| | | |
relatedUser__domainName | str
| | | |
comments__comment_str | str
| Code Block |
---|
join(comments__comment, ',') |
| comments__comment | |
comments__createdBy_str | str
| Code Block |
---|
join(comments__createdBy, ',') |
| comments__createdBy | |
comments__createdTime_str | str
| Code Block |
---|
join(comments__createdTime, ',') |
| comments__createdTime | |
evidence__entityType_str | str
| Code Block |
---|
join(evidence__entityType, ',') |
| evidence__entityType | |
evidence__evidenceCreationTime_str | str
| Code Block |
---|
join(evidence__evidenceCreationTime, ',') |
| evidence__evidenceCreationTime | |
evidence__sha1_str | str
| Code Block |
---|
join(evidence__sha1, ',') |
| evidence__sha1 | |
evidence__sha256_str | str
| Code Block |
---|
join(evidence__sha256, ',') |
| evidence__sha256 | |
evidence__fileName_str | str
| Code Block |
---|
join(evidence__fileName, ',') |
| evidence__fileName | |
evidence__filePath_str | str
| Code Block |
---|
join(evidence__filePath, ',') |
| evidence__filePath | |
evidence__processId_str | str
| Code Block |
---|
replace(replace(stringify(json(evidence__processId)), "[", ""), "]", "") |
| evidence__processId | |
evidence__processCommandLine_str | str
| Code Block |
---|
join(evidence__processCommandLine, ',') |
| evidence__processCommandLine | |
evidence__processCreationTime_str | str
| Code Block |
---|
join(evidence__processCreationTime, ',') |
| evidence__processCreationTime | |
evidence__parentProcessId_str | str
| Code Block |
---|
replace(replace(stringify(json(evidence__parentProcessId)), "[", ""), "]", "") |
| evidence__parentProcessId | |
evidence__parentProcessCreationTime_str | str
| Code Block |
---|
join(evidence__parentProcessCreationTime, ',') |
| evidence__parentProcessCreationTime | |
evidence__parentProcessFileName_str | str
| Code Block |
---|
join(evidence__parentProcessFileName, ',') |
| evidence__parentProcessFileName | |
evidence__parentProcessFilePath_str | str
| Code Block |
---|
join(evidence__parentProcessFilePath, ',') |
| evidence__parentProcessFilePath | |
evidence__ipAddress_str | str
| Code Block |
---|
join(evidence__ipAddress, ',') |
| evidence__ipAddress | |
evidence__url_str | str
| Code Block |
---|
join(evidence__url, ',') |
| evidence__url | |
evidence__registryKey_str | str
| Code Block |
---|
join(evidence__registryKey, ',') |
| evidence__registryKey | |
evidence__registryHive_str | str
| Code Block |
---|
join(evidence__registryHive, ',') |
| evidence__registryHive | |
evidence__registryValueType_str | str
| Code Block |
---|
join(evidence__registryValueType, ',') |
| evidence__registryValueType | |
evidence__registryValue_str | str
| Code Block |
---|
join(evidence__registryValue, ',') |
| evidence__registryValue | |
evidence__accountName_str | str
| Code Block |
---|
join(evidence__accountName, ',') |
| evidence__accountName | |
evidence__domainName_str | str
| Code Block |
---|
join(evidence__domainName, ',') |
| evidence__domainName | |
evidence__userSid_str | str
| Code Block |
---|
join(evidence__userSid, ',') |
| evidence__userSid | |
evidence__aadUserId_str | str
| Code Block |
---|
join(evidence__aadUserId, ',') |
| evidence__aadUserId | |
evidence__userPrincipalName_str | str
| Code Block |
---|
join(evidence__userPrincipalName, ',') |
| evidence__userPrincipalName | |
evidence__detectionStatus_str | str
| Code Block |
---|
join(evidence__detectionStatus, ',') |
| evidence__detectionStatus | |
hostchain | str
| | | ✓ |
tag | str
| | | ✓ |
rawMessage | str
| | | ✓ |