Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Company Product / service Valid tags

Carbon Black Endpoint Detection and Response

  • edr.carbonblack.alert+info
  • edr.carbonblack.binary+info
  • edr.carbonblack.feed+info
  • edr.carbonblack.ingress+info
  • edr.carbonblack.watchlist+info

Check more info about these parsers

Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon+info

  • edr.crowdstrike.cannon.asepvalueupdate+info

  • edr.crowdstrike.cannon.channelversionrequired+info

  • edr.crowdstrike.cannon.dnsrequest+info

  • edr.crowdstrike.cannon.endofprocess+info

  • edr.crowdstrike.cannon.neighborlistip4+info

  • edr.crowdstrike.cannon.networkconnectip4+info

  • edr.crowdstrike.cannon.other+info

  • edr.crowdstrike.cannon.processrollup2+info

  • edr.crowdstrike.cannon.processrollup2stats+info

  • edr.crowdstrike.cannon.sensorheartbeat+info

  • edr.crowdstrike.cannon.syntheticprocessrollup2+info

Check more info about these parsers

Cylance PROTECT 

Check more info about these parsers

Fireeye Endpoint Detection & Response

Check more info about these parsers

Minerva Labs

Minerva Labs anti-evasion platform

Check more info about these parsers

ObserveIT Insider Threat Detection

  • edr.observeit.events

Palo Alto Cortex XDR

  • edr.paloalto.cortex_xdr+info
  • edr.paloalto.cortex_xdr_agent+info

Check more info about these parsers

image2021-6-15_11-33-45.png

Symantec Endpoint Detection & Response

  • edr.symantec.events

...