Table of Contents | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
edr.crowdstrike.falconstreaming.incidents
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
incident_id |
| - |
incident_type |
| - |
cid |
| - |
host_ids |
| - |
hosts |
| - |
created |
| - |
start |
| - |
end |
| - |
state |
| - |
status |
| - |
tactics |
| - |
techniques |
| - |
objectives |
| - |
fine_score |
| - |
lmra_host_ids |
| - |
lm_types |
| - |
tags |
| - |
modified_timestamp |
| - |
users |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.incident_summary
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
State |
| - |
IncidentID |
| - |
IncidentStartTime |
| - |
IncidentEndTime |
| - |
FineScore |
| - |
FalconHostLink |
| - |
jsonEvent |
| - |
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
customerIDString |
|
|
| |||
offset |
|
|
| |||
eventType |
|
|
| |||
eventCreationTime |
|
|
| |||
version |
|
|
| |||
sensorId |
|
|
| |||
mobileDetectionId |
|
|
| |||
computerName |
|
|
| |||
userName |
|
|
| |||
contextTimeStamp |
|
|
| |||
detectId |
|
| compositeId detectId_aux | |||
detectName |
|
| detectName_aux name | |||
detectDescription |
|
| description detectDescription_aux | |||
compositeId |
|
|
| |||
name |
|
|
| |||
description |
|
|
| |||
tactic |
|
|
| |||
tacticId |
|
|
| |||
technique |
|
|
| |||
techniqueId |
|
|
| |||
objective |
|
|
| |||
severity |
|
|
| |||
falconHostLink |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
eventType |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
notificationId |
| - |
highlights_str |
| - |
matchedTimestamp |
| - |
ruleId |
| - |
ruleName |
| - |
ruleTopic |
| - |
rulePriority |
| - |
itemId |
| - |
itemType |
| - |
itemPostedTimestamp |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
SessionId |
| - |
UserName |
| - |
HostnameField |
| - |
StartTimestamp |
| - |
EndTimestamp |
| - |
Commands |
| - |
jsonEvent |
| - |
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
edr.crowdstrike.falconstreaming.scheduled_report_notification
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
userUUID |
| - |
userID |
| - |
executionID |
| - |
reportID |
| - |
reportName |
| - |
reportType |
| - |
reportFileReference |
| - |
status |
| - |
statusMessage |
| - |
executionStart |
| - |
executionDuration |
| - |
reportFileName |
| - |
resultCount |
| - |
resultID |
| - |
searchWindowStart |
| - |
searchWindowEnd |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
group_id |
| - |
group_name |
| - |
group_description |
| - |
group_assignment_rule |
| - |
old_group_assignment_rule |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
quarantined_file_id |
| - |
action_taken |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
quarantined_file_id |
| - |
action_taken |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |