Table of Contents | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
edr.crowdstrike.falconstreaming.user_activity_other
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
UserId |
| - |
UserIp |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.recon_notification_summary
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
notificationId |
| - |
highlights_str |
| - |
matchedTimestamp |
| - |
ruleId |
| - |
ruleName |
| - |
ruleTopic |
| - |
rulePriority |
| - |
itemId |
| - |
itemType |
| - |
itemPostedTimestamp |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
customerIDString |
|
|
| |||
offset |
|
|
| |||
eventCreationTime |
|
|
| |||
version |
|
|
| |||
eventType |
|
|
| |||
ServiceName |
|
|
| |||
OperationName |
|
|
| |||
UTCTimestamp |
|
|
| |||
Success |
|
|
| |||
UserId |
|
|
| |||
UserIp |
|
|
| |||
detection_id |
|
| detection_id_aux composite_id | |||
composite_id |
|
|
| |||
detects |
|
|
| |||
new_state |
|
|
| |||
assigned_to |
|
|
| |||
assigned_to_uid |
|
|
| |||
show_in_ui |
|
|
| |||
APIClientID |
|
|
| |||
AuditKeyValues |
|
|
| |||
jsonEvent |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
SensorId |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
policy_id |
| - |
devices_affected |
| - |
policy_priority |
| - |
old_policy_priority |
| - |
policy_name |
| - |
policy_description |
| - |
policy_platform |
| - |
policy_type |
| - |
policy_assignment_rule |
| - |
policy_enabled |
| - |
policy_settings_AdwareExecution |
| - |
old_policy_settings_AdwareExecution |
| - |
policy_settings_ApplicationExploitationActivity |
| - |
old_policy_settings_ApplicationExploitationActivity |
| - |
policy_settings_BackupDeletion |
| - |
old_policy_settings_BackupDeletion |
| - |
policy_settings_ChopperWebshell |
| - |
old_policy_settings_ChopperWebshell |
| - |
policy_settings_Cryptowall |
| - |
old_policy_settings_Cryptowall |
| - |
policy_settings_CustomBlacklisting |
| - |
old_policy_settings_CustomBlacklisting |
| - |
policy_settings_DriveByDownload |
| - |
old_policy_settings_DriveByDownload |
| - |
policy_settings_FileAnalysis |
| - |
old_policy_settings_FileAnalysis |
| - |
policy_settings_FileAttributeAnalysis |
| - |
old_policy_settings_FileAttributeAnalysis |
| - |
policy_settings_FileEncryption |
| - |
old_policy_settings_FileEncryption |
| - |
policy_settings_ForceASLR |
| - |
old_policy_settings_ForceASLR |
| - |
policy_settings_ForceDEP |
| - |
old_policy_settings_ForceDEP |
| - |
policy_settings_HeapSprayPreallocation |
| - |
old_policy_settings_HeapSprayPreallocation |
| - |
policy_settings_Locky |
| - |
old_policy_settings_Locky |
| - |
policy_settings_WindowsLogonBypassStickyKeys |
| - |
old_policy_settings_WindowsLogonBypassStickyKeys |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
cid |
| - |
aid |
| - |
created_timestamp |
| - |
closed_timestamp |
| - |
updated_timestamp |
| - |
status |
| - |
cve__id |
| - |
cve__base_score |
| - |
cve__severity |
| - |
cve__exploit_status |
| - |
app__product_name_version |
| - |
apps |
| - |
host_info__hostname |
| - |
host_info__local_ip |
| - |
host_info__machine_domain |
| - |
host_info__os_version |
| - |
host_info__ou |
| - |
host_info__site_name |
| - |
host_info__system_manufacturer |
| - |
host_info__groups |
| - |
host_info__tags |
| - |
host_info__platform |
| - |
remediation__ids |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falcon
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
metadata_customerIDString |
|
|
| |||
metadata_offset |
|
|
| |||
metadata_eventType |
|
|
| |||
metadata_eventCreationTime |
|
|
| |||
metadata_version |
|
|
| |||
event_ProcessStartTime |
|
|
| |||
event_ProcessEndTime |
|
|
| |||
event_ProcessId |
|
|
| |||
event_ParentProcessId |
|
|
| |||
event_ComputerName |
|
|
| |||
event_UserName |
|
|
| |||
event_DetectId |
|
| event_DetectId_aux event_CompositeId | |||
event_DetectName |
|
| event_Name event_DetectName_aux | |||
event_DetectDescription |
|
| event_DetectDescription_aux event_Description | |||
event_CompositeId |
|
|
| |||
event_Name |
|
|
| |||
event_Description |
|
|
| |||
event_Severity |
|
|
| |||
event_SeverityName |
|
|
| |||
event_FileName |
|
|
| |||
event_FilePath |
|
|
| |||
event_CommandLine |
|
|
| |||
event_SHA256String |
|
|
| |||
event_MD5String |
|
|
| |||
event_SHA1String |
|
|
| |||
event_MachineDomain |
|
|
| |||
event_ExecutablesWritten |
|
|
| |||
event_FalconHostLink |
|
|
| |||
event_SensorId |
|
|
| |||
event_IOCType |
|
|
| |||
event_IOCValue |
|
|
| |||
event_new_state |
|
|
| |||
event_quarantined_file_id |
|
|
| |||
event_action_taken |
|
|
| |||
event_target_name |
|
|
| |||
event_LocalIP |
|
|
| |||
event_MACAddress |
|
|
| |||
event_Tactic |
|
|
| |||
event_Technique |
|
|
| |||
event_Objective |
|
|
| |||
event_group_id |
|
|
| |||
event_group_name |
|
|
| |||
event_old_group_name |
|
|
| |||
event_group_description |
|
|
| |||
event_old_group_description |
|
|
| |||
event_group_assignment_rule |
|
|
| |||
event_old_group_assignment_rule |
|
|
| |||
event_policy_id |
|
|
| |||
event_policy_name |
|
|
| |||
event_old_policy_name |
|
|
| |||
event_policy_description |
|
|
| |||
event_policy_type |
|
|
| |||
event_policy_enabled |
|
|
| |||
event_policy_platform |
|
|
| |||
event_policy_assignment_rule |
|
|
| |||
event_policy_settings_ReleaseID |
|
|
| |||
event_old_policy_settings_ReleaseID |
|
|
| |||
event_policy_settings_UninstallProtection |
|
|
| |||
event_UserId |
|
|
| |||
event_UserIp |
|
|
| |||
event_OperationName |
|
|
| |||
event_ServiceName |
|
|
| |||
event_Success |
|
|
| |||
event_UTCTimestamp |
|
|
| |||
event_UTCTimestamp_formatted |
|
|
| |||
event_ScanResults_Engine_str |
|
| event_ScanResults_Engine | |||
event_ScanResults_ResultName_str |
|
| event_ScanResults_ResultName | |||
event_ScanResults_Version_str |
|
| event_ScanResults_Version | |||
event_ScanResults_Detected_str |
|
| event_ScanResults_Detected | |||
event_PatternDispositionDescription |
|
|
| |||
event_PatternDispositionValue |
|
|
| |||
event_PatternDispositionFlags_Indicator |
|
|
| |||
event_PatternDispositionFlags_Detect |
|
|
| |||
event_PatternDispositionFlags_InddetMask |
|
|
| |||
event_PatternDispositionFlags_SensorOnly |
|
|
| |||
event_PatternDispositionFlags_Rooting |
|
|
| |||
event_PatternDispositionFlags_KillProcess |
|
|
| |||
event_PatternDispositionFlags_KillSubProcess |
|
|
| |||
event_PatternDispositionFlags_QuarantineMachine |
|
|
| |||
event_PatternDispositionFlags_QuarantineFile |
|
|
| |||
event_PatternDispositionFlags_PolicyDisabled |
|
|
| |||
event_PatternDispositionFlags_KillParent |
|
|
| |||
event_PatternDispositionFlags_OperationBlocked |
|
|
| |||
event_PatternDispositionFlags_ProcessBlocked |
|
|
| |||
event_ParentImageFileName |
|
|
| |||
event_ParentCommandLine |
|
|
| |||
event_GrandparentImageFileName |
|
|
| |||
event_GrandparentCommandLine |
|
|
| |||
event_QuarantineFiles_ImageFileName_str |
|
| event_QuarantineFiles_ImageFileName | |||
event_QuarantineFiles_SHA256HashData_str |
|
| event_QuarantineFiles_SHA256HashData | |||
message |
|
| rawSource | |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
| rawSource | ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_type |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
FullFilePath |
| - |
FilePath |
| - |
FileName |
| - |
ImageFileName |
| - |
ImageSubsystem |
| - |
IntegrityLevel |
| - |
MD5HashData |
| - |
ParentAuthenticationId |
| - |
ParentProcessId |
| - |
ProcessCreateFlags |
| - |
ProcessEndTime |
| - |
ProcessParameterFlags |
| - |
ProcessStartTime |
| - |
ProcessSxsFlags |
| - |
RawProcessId |
| - |
SHA1HashData |
| - |
SHA256HashData |
| - |
SourceProcessId |
| - |
SourceThreadId |
| - |
TargetFileName |
| - |
TargetProcessId |
| - |
SessionProcessId |
| - |
TokenType |
| - |
UserSid |
| - |
ComputerName |
| - |
ClientComputerName |
| - |
FirstIP4Record |
| - |
PhysicalAddress |
| - |
ContextProcessId |
| - |
LocalAddressIP4 |
| - |
LocalPort |
| - |
Protocol |
| - |
RemoteAddressIP4 |
| - |
RemotePort |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
tagGroup |
| - |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
event_simpleName |
| - |
ContextTimeStamp |
| - |
ConfigStateHash |
| - |
aip |
| - |
SessionProcessId |
| - |
ConfigBuild |
| - |
PatternDisposition |
| - |
event_platform |
| - |
TargetProcessId |
| - |
PatternId |
| - |
Entitlements |
| - |
name |
| - |
id |
| - |
EffectiveTransmissionClass |
| - |
aid |
| - |
timestamp |
| - |
cid |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |