/
Endpoint Detection and Response

Endpoint Detection and Response

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company

Product/Service

Data tables

Company

Product/Service

Data tables


Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

    More info about these parsers


Cylance PROTECT 


Fireeye Endpoint Detection & Response


Minerva Labs anti-evasion platform


ObserveIT Insider Threat Detection

  • edr.observeit.events


Palo Alto Cortex XDR


Symantec Endpoint Detection & Response

  • edr.symantec.events