...
Field | Type | Extra field |
---|---|---|
eventdate |
| - |
machine |
| - |
activity_id |
| - |
agent_id |
| - |
aggregate_id |
| - |
cid |
| - |
composite_id |
| - |
confidence |
| - |
context_timestamp |
| - |
crawl_edge_ids_sensor |
| - |
crawl_vertex_ids_sensor |
| - |
crawled_timestamp |
| - |
created_timestamp |
| - |
data_domains |
| - |
description |
| - |
display_name |
| - |
end_time |
| - |
falcon_host_link |
| - |
id |
| - |
ldap_search_query_attack |
| - |
name |
| - |
objective |
| - |
pattern_id |
| - |
poly_id |
| - |
product |
| - |
scenario |
| - |
seconds_to_resolved |
| - |
seconds_to_triaged |
| - |
severity |
| - |
severity_name |
| - |
show_in_ui |
| - |
source_account_domain |
| - |
source_account_name |
| - |
source_account_object_guid |
| - |
source_account_object_sid |
| - |
source_account_upn |
| - |
source_endpoint_account_object_guid |
| - |
source_endpoint_account_object_sid |
| - |
source_endpoint_address_ipv4 |
| - |
source_endpoint_host_name |
| - |
source_endpoint_address_ip |
| - |
source_endpoint_sensor_id |
| - |
source_products |
| - |
source_vendors |
| - |
start_time |
| - |
status |
| - |
tactic |
| - |
tactic_id |
| - |
target_account_name |
| - |
target_domain_controller_host_name |
| - |
target_domain_controller_object_guid |
| - |
target_domain_controller_object_sid |
| - |
target_endpoint_account_object_guid |
| - |
target_endpoint_account_object_sid |
| - |
target_endpoint_host_name |
| - |
target_endpoint_sensor_id |
| - |
technique |
| - |
technique_id |
| - |
timestamp |
| - |
type |
| - |
updated_timestamp |
| - |
username |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
...
edr.crowdstrike.falconstreaming.auth_activity
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
target_name |
| - |
target_user_uuid |
| - |
target_cid |
| - |
roles |
| - |
scope |
| - |
actor_user |
| - |
actor_user_uuid |
| - |
actor_cid |
| - |
subscriptions |
| - |
APIClientID |
| - |
appId |
| - |
eventType2 |
| - |
partition |
| - |
offset2 |
| - |
id |
| - |
name |
| - |
trace_id |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
...