...
This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables:
Note |
---|
Extra fields Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns. |
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
originator |
|
orig | ||
host |
|
|
destination_ip |
ip4
|
| ||
destination_ipv4 |
| dest_ip | |
destination_port |
|
dest_port | |||
event_type |
|
| |
protocol |
| proto | |
source_ip |
|
|
source_ |
ipv4 |
|
src_ip |
source_port |
|
src_port | |||
timestamp |
|
| |
alert_category |
|
| |
alert_ |
revision |
|
alert_rev | |||
alert_severity |
|
| |
alert_signature |
|
| |
alert_signature_id |
|
| |
event_format |
|
| |
event_source |
|
| |
event_uuid |
|
| |
sensor_ipv4 |
|
| |
sensor_uuid |
|
| |
source_geo_city_name |
| src_city_name | |
source_geo_country_name |
|
src_country |
str
source_geo_latitude |
| src_lat | |
source_geo_longitude |
|
src_lon |
float8
destination_geo_city_name |
| dst_city_name |
str
destination_geo_country_name |
| dst_country |
str
destination_geo_latitude |
| dst_lat | |
destination_geo_longitude |
|
dst_lon |
float8
bytes_analyzed |
|
|
connection_uids |
|
conn_uids | ||
download |
|
|
file_id |
|
fid | ||
file_description |
|
|
file_name |
|
filename | |||
md5 |
|
| |
mime_type |
|
| |
bro_protocol |
| bro_proto | |
recipient_destination_ip |
|
|
recipient_destination_ |
ipv4 |
|
rx_host | |
recipient_destination_port |
|
rx_port | |||
sha1 |
|
| |
stored_as |
|
| |
transfer_protocol |
| transfer_proto | |
transfer_source_ip |
|
|
transfer_source_ |
ipv4 |
|
tx_host | |
transfer_source_port |
|
tx_port | |
cause_message |
|
CauseMessage |
determinant |
|
Determinant |
parse_status |
|
ParseStatus |
sha256 |
|
SHA256 |
sample_format |
|
SampleFormat | |
sample_scoring_activity_version |
|
SampleScoringActivityVersion | |
sample_scoring_version |
|
SampleScoringVersion |
score |
|
Score |
status_cause |
|
StatusCause | |
raise_exception_imports |
|
RaiseExceptionImports | |
os_info_imports |
|
OSInfoImports | |
debug_check_imports |
|
DebugCheckImports | |
terminate_process_imports |
|
TerminateProcessImports | |
codepage_lookup_imports |
|
CodepageLookupImports | |||
hostchain |
|
| |
url |
|
|
content_type |
|
http_content_type | ||
method |
|
http_method | ||
user_agent |
|
http_user_agent | ||
hostname |
|
|
json_event |
|
jsonEvent | |||
tag |
|
| ✓ |
Note |
---|
Extra fields Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns. |
Field transformations
Even though all source tables have several features in common, they have some particularities that make it necessary to undergo a set of transformations to harmonize them for the union table. The most common transformations comprise changes in the data type or the application of rules when several columns in the source table feed a single column in the union table. You can find below the detailed list of transformations in each source table.
...
Anchor | ||||
---|---|---|---|---|
|
Field in union table | Field in source table | Field transformation | Type | Extra fields |
---|---|---|---|---|
eventdate | eventdate |
|
|
originator |
originator |
|
"brocata"
| |||
host | host |
|
|
destination_ip | dest_ip |
|
| ||
destination_ipv4 | destination_ipv4 |
|
|
destination_port |
destination_port |
|
| ||
event_type | event_type |
|
|
protocol |
protocol |
|
|
source_ip | src_ip |
|
| ||
source_ipv4 | source_ipv4 |
|
|
source_port |
source_port |
|
| |||
timestamp | timestamp |
|
| |
alert_category | category |
|
| |
alert_ |
revision |
rev
alert_revision |
|
| ||||
alert_severity | severity |
|
| |||
alert_signature | signature |
|
| |||
alert_signature_id | signature_id |
|
| |||
event_format | event_format |
|
| |||
event_source | event_source |
|
| |||
event_uuid | event_uuid |
|
| |||
sensor_ipv4 | sensor_ipv4 |
|
| |||
sensor_uuid | sensor_uuid |
|
|
source_geo_city_name |
source_geo_city_name |
|
|
source_geo_country_name |
source_geo_country_name |
|
|
source_geo_ |
latitude |
source_geo_ |
latitude |
|
|
source_geo_ |
longitude |
source_geo_ |
longitude |
|
|
destination_geo_city_name |
destination_geo_city_name |
|
|
destination_geo_country_name |
destination_geo_country_name |
|
|
destination_geo_ |
latitude |
destination_geo_ |
latitude |
|
|
destination_geo_ |
longitude |
destination_geo_ |
longitude |
|
| |||
bytes_analyzed | - |
|
|
connection_uids |
-
connection_uids |
|
| |||
download | false |
|
|
fid
-
file_id | file_id |
|
| ||
file_description | - |
|
|
filename
-
file_name | file_name |
|
| |||
md5 | - |
|
| |||
mime_type | - |
|
| |||
bro_protocol | bro |
_protocol |
|
| ||
recipient_destination_ip | - |
|
|
|
recipient_destination_ |
-
Code Block |
---|
null(ip4("0.0.0.0")) |
ip4
rx_port
-
Code Block |
---|
null("") |
ipv4 | recipient_destination_ipv4 |
|
| |||
recipient_destination_port | recipient_destination_port |
|
| |||
sha1 | - |
|
| |||
stored_as | - |
|
| |||
transfer_protocol | transfer_protocol |
|
| |||
transfer_source_ |
ip | - |
|
|
|
transfer_source_ |
-
Code Block |
---|
null(ip4("0.0.0.0")) |
ip4
tx_port
-
Code Block |
---|
null("") |
str
CauseMessage
-
Code Block |
---|
null("") |
str
Determinant
-
Code Block |
---|
null("") |
str
ParseStatus
-
Code Block |
---|
null("") |
str
SHA256
-
Code Block |
---|
null("") |
str
SampleFormat
-
Code Block |
---|
null("") |
str
SampleScoringActivityVersion
-
Code Block |
---|
null(int8(0)) |
int8
SampleScoringVersion
-
Code Block |
---|
null(int8(0)) |
int8
Score
-
Code Block |
---|
null(float8(0)) |
float8
StatusCause
-
Code Block |
---|
null("") |
str
RaiseExceptionImports
false
Code Block |
---|
null(false) |
bool
OSInfoImports
false
Code Block |
---|
null(false) |
bool
DebugCheckImports
false
Code Block |
---|
null(false) |
bool
TerminateProcessImports
false
Code Block |
---|
null(false) |
bool
CodepageLookupImports
false
Code Block |
---|
null(false) |
ipv4 | transfer_source_ipv4 |
|
| |
transfer_source_port | transfer_source_port |
|
| |
cause_message | cause_message |
|
| |
determinant | determinant |
|
| |
parse_status | parse_status |
|
| |
sha256 | sha256 |
|
| |
sample_format | sample_format |
|
| |
sample_scoring_activity_version | sample_scoring_activity_version |
|
| |
sample_scoring_version | sample_scoring_version |
|
| |
score | score |
|
| |
status_cause | status_cause |
|
| |
raise_exception_imports | raise_exception_imports |
|
| |
os_info_imports | os_info_imports |
|
| |
debug_check_imports | debug_check_imports |
|
| |
terminate_process_imports | terminate_process_imports |
|
| |
codepage_lookup_imports | codepage_lookup_imports |
|
| |
hostchain | hostchain |
|
| |
url | url |
|
|
content_type |
content_type |
|
|
method |
method |
|
|
user_agent |
user_agent |
|
| |
hostname | hostname |
|
|
jsonEvent
json_event | json_event |
|
| |
tag | tag |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field in union table | Field in source table | Field transformation | Type | Extra fields |
---|---|---|---|---|
eventdate | eventdate |
|
|
originator |
originator |
|
"burocata"
| ||||||
host | host |
|
| |||
destination_ip | dest_ip |
|
| |||
destination_ipv4 | destination_ipv4 |
|
|
destination_port |
destination_port |
|
| |
event_type | event_type |
|
|
protocol |
protocol |
|
| ||||
source_ip | src_ip |
|
| |||
source_ipv4 | source_ipv4 |
|
|
source_port |
source_port |
|
| ||
timestamp | timestamp |
|
| |
alert_category | alert_category |
|
| |
alert_ |
revision | alert_ |
revision |
|
| ||||
alert_severity | alert_severity |
|
| |||
alert_signature | alert_signature |
|
| |||
alert_signature_id | alert_signature_id |
|
| |||
event_format | event_format |
|
| |||
event_source | event_source |
|
| |||
event_uuid | event_uuid |
|
| |||
sensor_ipv4 | sensor_ipv4 |
|
| |||
sensor_uuid | sensor_uuid |
|
|
source_geo_city_name | source_geo_city_name |
|
|
source_geo_country_name | source_geo_country_name |
|
|
source_geo_ |
latitude | source_geo_latitude |
|
|
source_geo_ |
longitude | source_geo_longitude |
|
|
destination_geo_city_name |
-
destination_geo_city_name |
|
|
destination_geo_country |
-
Code Block |
---|
null("") |
str
dst_lat
-
Code Block |
---|
null(float8(0)) |
float8
dst_lon
-
_name | destination_geo_country_name |
|
| |
destination_geo_latitude | destination_geo_latitude |
|
| |
destination_geo_longitude | destination_geo_longitude |
|
| |
bytes_analyzed | bytes_analyzed |
|
|
connection_uids |
connection_uids |
|
| |
download | download |
|
|
fid
file_id | file_id |
|
| |
file_description | file_description |
|
|
filename
file_name | file_name |
|
| |
md5 | md5 |
|
| |
mime_type | mime_type |
|
| |
bro_ |
protocol | bro_ |
protocol |
|
| ||||
recipient_destination_ip | rx_host |
|
| |||
recipient_destination_ipv4 | recipient_destination_ipv4 |
|
|
recipient_destination_port |
recipient_destination_port |
|
| ||
sha1 | sha1 |
|
| |
stored_as | stored_as |
|
| |
transfer_ |
protocol | transfer_ |
protocol |
|
| ||||
transfer_source_ip | tx_host |
|
| |||
transfer_source_ipv4 | transfer_source_ipv4 |
|
|
transfer_source_port |
transfer_source_port |
|
|
CauseMessage
cause_message | cause_message |
|
|
determinant |
determinant |
|
|
ParseStatus
parse_status | parse_status |
|
|
sha256 |
sha256 |
|
|
SampleFormat
sample_format | sample_format |
|
|
SampleScoringActivityVersion
SampleScoringActivityVersion
Code Block |
---|
int8(SampleScoringActivityVersion) |
int8
SampleScoringVersion
SampleScoringVersion
Code Block |
---|
int8(SampleScoringVersion) |
int8
Score
sample_scoring_activity_version | sample_scoring_activity_version |
|
| |
sample_scoring_version | sample_scoring_version |
|
| |
score | score |
|
|
StatusCause
status_cause | status_cause |
|
|
RaiseExceptionImports
raise_exception_imports | raise_exception_imports |
|
|
OSInfoImports
os_info_imports | os_info_imports |
|
|
DebugCheckImports
debug_check_imports | debug_check_imports |
|
|
TerminateProcessImports
terminate_process_imports | terminate_process_imports |
|
|
CodepageLookupImports
codepage_lookup_imports | codepage_lookup_imports |
|
| |||
hostchain | - |
|
| |||
url | - |
|
|
content_type | content_type |
-
|
|
method |
-
method |
|
|
user_agent | user_agent |
-
|
| ||||
hostname | - |
|
|
jsonEvent
json_event | json_event |
|
| |
tag | tag |
|
| ✓ |