...
Product / Service | Tags | Data tables |
---|---|---|
Trellix Endpoint Security |
|
|
Trellix Complete Data Protection |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in this tablethese tables:
dlp.trellix.epo.incident
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
detectedutc |
|
|
device_description |
|
|
cancelled_action_reason |
|
|
|
| |
number_of_rules |
|
|
receivedutc |
|
|
source_display_name |
|
|
eventtimelocal |
|
|
manager |
|
|
total_matches |
|
|
connectivity_state |
|
|
threatseverity |
|
|
event_global_id |
|
|
store_file |
|
|
number_of_classifications |
|
|
source_username |
|
|
total_content_size |
|
|
threattype |
|
|
threateventid |
|
|
usb_class |
|
|
policy_revision |
|
|
cancelled_action |
|
|
actual_action |
|
|
instance_id |
|
|
autoid |
|
|
analyzerversion |
|
|
unplug_utc_time |
|
|
agentguid |
|
|
sid |
|
|
rawmac |
|
|
time_zone |
|
|
analyzeripv6 |
|
|
analyzeripv4 |
|
|
class_guid |
|
|
total_unique |
|
|
policy_name |
|
|
analyzerhostname |
|
|
tenantguid |
|
|
destination |
|
|
bus_type |
|
|
rule_names |
|
|
device_id |
|
|
vendor_id |
|
|
reportingproduct |
|
|
sourceipv4 |
|
|
dest_user_email |
|
|
manager_manager |
|
|
device_serial_number |
|
|
volume_serial_number |
|
|
analyzer |
|
|
display_name |
|
|
tenantid |
|
|
nodepath |
|
|
evidence_count |
|
|
ou |
|
|
rule_set_names |
|
|
compatible_id |
|
|
analyzerengineversion |
|
|
volume_label |
|
|
threatactiontaken |
|
|
threat_name |
|
|
analyzerdatversion |
|
|
class_display_name |
|
|
autoguid |
|
|
file_system_type |
|
|
plug_utc_time |
|
|
user_principal_name |
|
|
targetipv4 |
|
|
policy_id |
|
|
at_devo_environment |
|
|
at_devo_pulling_id |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
dlp.trellix.dpim.incident
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
machine |
|
|
type |
|
|
id |
|
|
attributes_action_taken |
|
|
attributes_agent_guid |
|
|
attributes_agent_version_ip |
|
|
attributes_agent_version_ipv4 |
|
|
attributes_agent_version_ipv6 |
|
|
attributes_connectivity |
|
|
attributes_destination |
|
|
attributes_event_global_id |
|
|
attributes_evidence_storage_id |
|
|
attributes_expected_action |
|
|
attributes_failure_reason |
|
|
attributes_incident_origin |
|
|
attributes_incident_type |
|
|
attributes_insertion_time |
|
|
attributes_last_update_time |
|
|
attributes_local_time |
|
|
attributes_match_url |
|
|
attributes_severity |
|
|
attributes_source |
|
|
attributes_timezone |
|
|
attributes_total_match_count |
|
|
attributes_utc_time |
|
|
attributes_workflow_id |
|
|
relationships_application_data_type |
|
|
relationships_application_data_id |
|
|
relationships_application_file_access_data_type |
|
|
relationships_application_file_access_data_id |
|
|
relationships_capture_search_data_type |
|
|
relationships_capture_search_data_id |
|
|
relationships_classification_matches_data |
|
|
relationships_clipboard_data_type |
|
|
relationships_clipboard_data_id |
|
|
relationships_cloud_data_type |
|
|
relationships_cloud_data_id |
|
|
relationships_collaboration_data_type |
|
|
relationships_collaboration_data_id |
|
|
relationships_comments_data |
|
|
relationships_device_data_type |
|
|
relationships_device_data_id |
|
|
relationships_email_data_type |
|
|
relationships_email_data_id |
|
|
relationships_endpoint_data_type |
|
|
relationships_endpoint_data_id |
|
|
relationships_event_user_data_type |
|
|
relationships_event_user_data_id |
|
|
relationships_evidence_data |
|
|
relationships_iam_role_reviewer_data_type |
|
|
relationships_iam_role_reviewer_data_id |
|
|
relationships_iam_user_reviewer_data_type |
|
|
relationships_iam_user_reviewer_data_id |
|
|
relationships_mobile_device_data_type |
|
|
relationships_mobile_device_data_id |
|
|
relationships_ndlp_appliance_data_type |
|
|
relationships_ndlp_appliance_data_id |
|
|
relationships_network_comm_data_type |
|
|
relationships_network_comm_data_id |
|
|
relationships_network_share_data_type |
|
|
relationships_network_share_data_id |
|
|
relationships_policy_data_type |
|
|
relationships_policy_data_id |
|
|
relationships_print_data_type |
|
|
relationships_print_data_id |
|
|
relationships_removable_storage_data_type |
|
|
relationships_removable_storage_data_id |
|
|
relationships_resolution_data_type |
|
|
relationships_resolution_data_id |
|
|
relationships_rules_data |
|
|
relationships_scan_data_type |
|
|
relationships_scan_data_id |
|
|
relationships_screen_capture_data_type |
|
|
relationships_screen_capture_data_id |
|
|
relationships_status_data_type |
|
|
relationships_status_data_id |
|
|
relationships_web_post_data_type |
|
|
relationships_web_post_data_id |
|
|
links_self |
|
|
at_devo_pulling_id |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |