Introduction
The tags beginning with endpoint.bitdefender
identify events generated by Bitdefender.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed asendpoint.bitdefender
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
...
Technology
...
Brand
...
Type
...
Subtype
...
endpoint
...
bitdefender
agent
...
alert
...
detection
...
modify_value
...
network_connection
...
file_modify
...
log_out
...
log_on
...
rca_insight_event
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data tableProduct / Service | Tags | Data tables |
---|
Bitdefender | endpoint.bitdefender.agent
| endpoint.bitdefender.agent
|
endpoint.bitdefender.agent.active_host
| endpoint.bitdefender.agent.active_host
|
endpoint.bitdefender.agent.alert
| endpoint.bitdefender.agent.alert
|
endpoint.bitdefender.agent.connection_connect
| endpoint.bitdefender.agent.connection_connect
|
endpoint.bitdefender.agent.ctc_raw_process_create
|
process_create
rca_insight
filescan_detection
terminate_process
file_delete
file_read
file_create
file_move
connection_connec
tinterface_change
user_logout
process_signa
linterface_added
process_create_fork
reg_delete_key
service_added
user_session_list
process_create_execve
user_account_settings_change
reg_delete_value
reg_modify_value
network_interfaces
gravityzone | |
These are the valid tags and corresponding data tables that will receive the parsers' data:
endpoint.bitdefender.agent.ctc_raw_process_create
|
endpoint.bitdefender.detection
| endpoint.bitdefender.detection
|
endpoint.bitdefender.agent.external_notification_on_process
| endpoint.bitdefender.agent.external_notification_on_process
|
endpoint.bitdefender.agent.
|
alertfile_create
| endpoint.bitdefender.agent.
|
alertfile_create
|
endpoint.bitdefender.agent.
|
detectionfile_delete
| endpoint.bitdefender.agent.
|
detectionfile_delete
|
endpoint.bitdefender.modify_value
| endpoint.bitdefender.modify_value
|
endpoint.bitdefender.agent.
|
networkconnectionmodify
| endpoint.bitdefender.agent.
|
networkconnectionmodify
|
endpoint.bitdefender.agent.file_
|
modifymove
| endpoint.bitdefender.agent.file_
|
modifymove
|
endpoint.bitdefender.agent.
|
logoutread
| endpoint.bitdefender.agent.
|
logoutread
|
endpoint.bitdefender.agent.
|
logondetection
| endpoint.bitdefender.agent.
|
logondetection
|
endpoint.bitdefender.agent.
|
rca_insight_eventgeneric_logging
| endpoint.bitdefender.agent.generic_logging
|
endpoint.bitdefender.agent.
|
rcainsight_eventadded
| endpoint.bitdefender.agent.
|
ctc_raw_process_createinterface_added
|
endpoint.bitdefender.agent.
|
ctc_raw_process_createinterface_change
| endpoint.bitdefender.agent.
|
processcreatechange
|
endpoint.bitdefender.agent.
|
processcreateon
| endpoint.bitdefender.agent.
|
rcainsighton
|
endpoint.bitdefender.agent.
|
rcainsightout
| endpoint.bitdefender.agent.
|
filescandetectionout
|
endpoint.bitdefender.agent.
|
filescandetectionfailed
| endpoint.bitdefender.agent.
|
terminateprocessfailed
|
endpoint.bitdefender.agent.
|
terminateprocessconnection
| endpoint.bitdefender.agent.
|
filedeleteconnection
|
endpoint.bitdefender.agent.
|
filedeleteinterfaces
| endpoint.bitdefender.agent.
|
filereadinterfaces
|
endpoint.bitdefender.agent.
|
filereadcreate
| endpoint.bitdefender.agent.
|
fileprocess_create
|
endpoint.bitdefender.agent.
|
fileprocess_create_execve
| endpoint.bitdefender.agent.
|
filemoveexecve
|
endpoint.bitdefender.agent.
|
filemovefork
| endpoint.bitdefender.agent.
|
connectionconnectfork
|
endpoint.bitdefender.agent.
|
connectionconnectsignal
| endpoint.bitdefender.agent.
|
interfacechangesignal
|
endpoint.bitdefender.agent.
|
interfacechangeinsight
| endpoint.bitdefender.agent.
|
userlogoutinsight
|
endpoint.bitdefender.agent.
|
userlogoutevent
| endpoint.bitdefender.agent.
|
processsignalevent
|
endpoint.bitdefender.agent.
|
processsignalkey
| endpoint.bitdefender.agent.
|
interfaceaddedkey
|
endpoint.bitdefender.agent.
|
interfaceaddedvalue
| endpoint.bitdefender.agent.
|
processcreateforkvalue
|
endpoint.bitdefender.agent.
|
processcreateforkvalue
| endpoint.bitdefender.agent.reg_
|
deletekeyvalue
|
endpoint.bitdefender.agent.
|
regdeletekeycreate
| endpoint.bitdefender.agent.
|
serviceaddedcreate
|
endpoint.bitdefender.agent.service_added
| endpoint.bitdefender.agent.
|
usersession_listadded
|
endpoint.bitdefender.agent.
|
usersession_listprocess
| endpoint.bitdefender.agent.terminate_process
|
_create_execve |
endpoint.bitdefender.agent.
|
processcreateexecvechange
| endpoint.bitdefender.agent.user_account_settings_change
|
endpoint.bitdefender.agent.user_
|
account_settings_changelogout
| endpoint.bitdefender.agent.user_logout
|
endpoint.bitdefender.agent.user_session_list
| endpoint.bitdefender.agent.
|
regdeletevaluelist
|
endpoint.bitdefender.agent.
|
regdeletevaluelogging
| endpoint.bitdefender.agent.
|
regmodify_valuespecific_logging
|
endpoint.bitdefender.agent.xrca
| endpoint.bitdefender.agent.xrca
|
endpoint.bitdefender.agent.
|
reg_modify_valuexrca_event
| endpoint.bitdefender.agent.xrca_event
|
endpoint.bitdefender.agent.
|
networkinterfacesvalue
| endpoint.bitdefender.agent.
|
networkinterfacesvalue
|
endpoint.bitdefender.gravityzone.product_modules_status
| endpoint.bitdefender.gravityzone.product_modules_status
|