Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The full tag must have 3 levels. The first two are fixed asedr.crowdstrike. The third level identifies the type of events sent, and the fourth level indicates the event subtype.

Product / Services

Tags

Data tables

Crodwstrike

Crowdstrike

edr.crowdstrike.falconstreaming.agents

edr.crowdstrike.falconstreaming.auth_activity

edr.crowdstrike.falconstreaming.behaviors

edr.crowdstrike.falconstreaming.customer_ioc

edr.crowdstrike.falconstreaming.detection_summary

edr.crowdstrike.falconstreaming.external_api

edr.crowdstrike.falconstreaming.firewall_match

edr.crowdstrike.falconstreaming.identity_protection

edr.crowdstrike.falconstreaming.idp_detection_summary

edr.crowdstrike.falconstreaming.incidents

edr.crowdstrike.falconstreaming.incident_summary

edr.crowdstrike.falconstreaming.mobile_detection_summary

edr.crowdstrike.falconstreaming.other

edr.crowdstrike.falconstreaming.recon_notification_summary

edr.crowdstrike.falconstreaming.remote_response_session

edr.crowdstrike.falconstreaming.scheduled_report_notification

edr.crowdstrike.falconstreaming.user_activity_groups

edr.crowdstrike.falconstreaming.user_activity_quarantined_files

edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy

edr.crowdstrike.falconstreaming.user_activity_other

edr.crowdstrike.falconstreaming.recon_notification_summary

edr.crowdstrike.falconstreaming.user_activity_devices

edr.crowdstrike.falconstreaming.user_activity_detections

edr.crowdstrike.falconstreaming.user_activity_ip_whitelist

edr.crowdstrike.falconstreaming.vulnerabilities

edr.crowdstrike.falcon

edr.crowdstrike.cannon

edr.crowdstrike.cannon.associateindicator

edr.crowdstrike.cannon.associatetreeidwithroot

edr.crowdstrike.cannon.asepvalueupdate

edr.crowdstrike.cannon.channelversionrequired

edr.crowdstrike.cannon.detectionexcluded

edr.crowdstrike.cannon.dnsrequest

edr.crowdstrike.cannon.endofprocess

edr.crowdstrike.cannon.neighborlistip4

edr.crowdstrike.cannon.networkconnectip4

edr.crowdstrike.cannon.other

edr.crowdstrike.cannon.processrollup2

edr.crowdstrike.cannon.processrollup2stats

edr.crowdstrike.cannon.sensorheartbeat

edr.crowdstrike.cannon.syntheticprocessrollup2

edr.crowdstrike.falconstreaming.agents

edr.crowdstrike.falconstreaming.auth_activity

edr.crowdstrike.falconstreaming.behaviors

edr.crowdstrike.falconstreaming.customer_ioc

edr.crowdstrike.falconstreaming.detection_summary

edr.crowdstrike.falconstreaming.external_api

edr.crowdstrike.falconstreaming.firewall_match

edr.crowdstrike.falconstreaming.identity_protection

edr.crowdstrike.falconstreaming.idp_detection_summary

edr.crowdstrike.falconstreaming.incidents

edr.crowdstrike.falconstreaming.incident_summary

edr.crowdstrike.falconstreaming.mobile_detection_summary

edr.crowdstrike.falconstreaming.other

edr.crowdstrike.falconstreaming.recon_notification_summary

edr.crowdstrike.falconstreaming.remote_response_session

edr.crowdstrike.falconstreaming.scheduled_report_notification

edr.crowdstrike.falconstreaming.user_activity_groups

edr.crowdstrike.falconstreaming.user_activity_quarantined_files

edr.crowdstrike.falconstreaming.user_activity_sensor_update_policy

edr.crowdstrike.falconstreaming.user_activity_other

edr.crowdstrike.falconstreaming.recon_notification_summary

edr.crowdstrike.falconstreaming.user_activity_devices

edr.crowdstrike.falconstreaming.user_activity_detections

edr.crowdstrike.falconstreaming.user_activity_ip_whitelist

edr.crowdstrike.falconstreaming.vulnerabilities

edr.crowdstrike.falcon

edr.crowdstrike.cannon

edr.crowdstrike.cannon.associateindicator

edr.crowdstrike.cannon.associatetreeidwithroot

edr.crowdstrike.cannon.asepvalueupdate

edr.crowdstrike.cannon.channelversionrequired

edr.crowdstrike.cannon.detectionexcluded

edr.crowdstrike.cannon.dnsrequest

edr.crowdstrike.cannon.endofprocess

edr.crowdstrike.cannon.neighborlistip4

edr.crowdstrike.cannon.networkconnectip4

edr.crowdstrike.cannon.other

edr.crowdstrike.cannon.processrollup2

edr.crowdstrike.cannon.processrollup2stats

edr.crowdstrike.cannon.sensorheartbeat

edr.crowdstrike.cannon.syntheticprocessrollup2

How is the data sent to Devo?

...