Field | Type | Source field name | Extra field |
---|
eventdate | timestamp
| | |
rawMessage | str
| | ✓ |
hostchain | str
| | ✓ |
hostname | str
| | |
priorityCode | str
| | |
cefTag | str
| | |
cefVersion | str
| | |
embDeviceVendor | str
| | |
embDeviceProduct | str
| | |
deviceVersion | str
| | |
signatureID | str
| | |
name | str
| | |
severity | str
| | |
_cefVer | str
| | |
act | str
| | |
app | str
| | |
cat | str
| | |
c6a1Label | str
| | |
c6a1 | str
| | |
c6a2Label | str
| | |
c6a2 | str
| | |
c6a3Label | str
| | |
c6a3 | str
| | |
c6a4Label | str
| | |
c6a4 | str
| | |
cfp1Label | str
| | |
cfp1 | float8
| | |
cfp2Label | str
| | |
cfp2 | float8
| | |
cfp3Label | str
| | |
cfp3 | float8
| | |
cfp4Label | str
| | |
cfp4 | float8
| | |
cn1Label | str
| | |
cn1 | int8
| | |
cn2Label | str
| | |
cn2 | int8
| | |
cn3Label | str
| | |
cn3 | int8
| | |
cnt | int4
| | |
cs1Label | str
| | |
cs1 | str
| | |
cs2Label | str
| | |
cs2 | str
| | |
cs3Label | str
| | |
cs3 | str
| | |
cs4Label | str
| | |
cs4 | str
| | |
cs5Label | str
| | |
cs5 | str
| | |
cs6Label | str
| | |
cs6 | str
| | |
destinationDnsDomain | str
| | |
destinationServiceName | str
| | |
destinationTranslatedAddress | ip4
| | |
destinationTranslatedPort | int4
| | |
deviceCustomDate1Label | str
| | |
deviceCustomDate1 | timestamp
| | |
deviceCustomDate2Label | str
| | |
deviceCustomDate2 | timestamp
| | |
deviceDirection | int4
| | |
deviceDnsDomain | str
| | |
deviceExternalId | str
| | |
deviceInboundInterface | str
| | |
deviceMacAddress | str
| | |
deviceNtDomain | str
| | |
deviceOutboundInterface | str
| | |
deviceProcessName | str
| | |
deviceTranslatedAddress | ip4
| | |
dhost | str
| | |
dmac | str
| | |
dntdom | str
| | |
dpid | int4
| | |
dpriv | str
| | |
dproc | str
| | |
dst | ip4
| | |
duid | str
| | |
duser | str
| | |
dvchost | str
| | |
dvc | ip4
| | |
dvcpid | int4
| | |
end | timestamp
| | |
deviceFacility | str
| | |
externalId | str
| | |
fileCreateTime | timestamp
| | |
fileHash | str
| | |
fileId | str
| | |
fileModificationTime | timestamp
| | |
filePath | str
| | |
filePermission | str
| | |
fileType | str
| | |
fname | str
| | |
fsize | int8
| | |
in | int8
| | |
msg | str
| | |
oldFileCreateTime | timestamp
| | |
oldFileHash | str
| | |
oldFileId | str
| | |
oldFileModificationTime | timestamp
| | |
oldFileName | str
| | |
oldFilePath | str
| | |
oldFilePermission | str
| | |
oldFileSize | int8
| | |
oldFileType | str
| | |
outcome | str
| | |
out | int8
| | |
proto | str
| | |
reason | str
| | |
requestClientApplication | str
| | |
requestCookies | str
| | |
requestMethod | str
| | |
request | str
| | |
rt | timestamp
| | |
shost | str
| | |
smac | str
| | |
sntdom | str
| | |
sourceDnsDomain | str
| | |
sourceServiceName | str
| | |
sourceTranslatedAddress | ip4
| | |
sourceTranslatedPort | int4
| | |
spid | int4
| | |
spriv | str
| | |
sproc | str
| | |
spt | int4
| | |
src | ip4
| | |
start | timestamp
| | |
suid | str
| | |
suser | str
| | |
catdt | str
| | |
deviceDomain | str
| | |
deviceSeverity | str
| | |
dpt | int4
| | |
dtz | str
| | |
dvcmac | str
| | |
endTime | str
| | |
eventId | str
| | |
flexNumber1 | str
| | |
flexNumber1Label | str
| | |
flexNumber2 | str
| | |
flexNumber2Label | str
| | |
flexString1 | str
| | |
flexString1Label | str
| | |
flexString2 | str
| | |
flexString2Label | str
| | |
modelConfidence | int4
| | |
priority | int4
| | |
relevance | int4
| | |
requestContext | str
| | |
sessionId | str
| | |
slat | float8
| | |
slong | float8
| | |
dlat | float8
| | |
dlong | float8
| | |
sourceGeoCountryCode | str
| | |
sourceGeoLocationInfo | str
| | |
sourceGeoPostalCode | str
| | |
sourceGeoRegionCode | str
| | |
destinationGeoCountryCode | str
| | |
destinationGeoLocationInfo | str
| | |
destinationGeoPostalCode | str
| | |
destinationGeoRegionCode | str
| | |
agt | ip4
| | |
ahost | str
| | |
art | str
| | |
atz | str
| | |
mrt | timestamp
| | |
categoryBehavior | str
| | |
categoryCustomFormatField | str
| | |
categoryDeviceGroup | str
| | |
categoryObject | str
| | |
categoryOutcome | str
| | |
categorySignificance | str
| | |
categoryTechnique | str
| | |
categoryTupleDescription | str
| | |
assetCriticality | str
| | |
customerID | str
| | |
customerURI | str
| | |
tag | str
| cefTag | ✓ |