...
cef1.carbonBlack.protection
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
priorityCode |
| |
cefTag |
| |
cefVersion |
| |
embDeviceVendor |
| |
embDeviceProduct |
| |
deviceVersion |
| |
signatureID |
| |
name |
| |
severity |
| |
_cefVer |
| |
cat |
| |
cfp1Label |
| |
cfp1 |
| |
cfp2Label |
| |
cfp2 |
| |
cs1Label |
| |
cs1 |
| |
cs2Label |
| |
cs2 |
| |
cs3Label |
| |
cs3 |
| |
cs5Label |
| |
cs5 |
| |
deviceProcessName |
| |
dhost |
| |
dst |
| |
duser |
| |
dvchost |
| |
dvc |
| |
externalId |
| |
fileHash |
| |
fileId |
| |
filePath |
| |
fname |
| |
msg |
| |
rt |
| |
sproc |
| |
start |
| |
ad_prevalence |
| |
agentZoneURI |
| |
agt |
| |
ahost |
| |
aid |
| |
amac |
| |
art |
| |
at |
| |
atz |
| |
av |
| |
destinationZoneURI |
| |
deviceSeverity |
| |
deviceZoneURI |
| |
dtz |
| |
eventId |
| |
flexString1 |
| |
flexString1Label |
| |
flexString2 |
| |
flexString2Label |
| |
hostchain |
| ✓ |
rawMessage |
| ✓ |