Document toolboxDocument toolbox

Endpoint Detection and Response

This group includes tags that start with the level edr. These tags identify data generated by Endpoint Detection and Response (EDR) systems.

Company Product / service Valid tags

Carbon Black Endpoint Detection and Response

  • edr.carbonblack.alert
  • edr.carbonblack.binary
  • edr.carbonblack.feed
  • edr.carbonblack.ingress
  • edr.carbonblack.watchlist

Check more info about these parsers

Crowdstrike Endpoint Detection & Response

  • edr.crowdstrike.cannon

  • edr.crowdstrike.cannon.asepvalueupdate

  • edr.crowdstrike.cannon.channelversionrequired

  • edr.crowdstrike.cannon.dnsrequest

  • edr.crowdstrike.cannon.endofprocess

  • edr.crowdstrike.cannon.neighborlistip4

  • edr.crowdstrike.cannon.networkconnectip4

  • edr.crowdstrike.cannon.other

  • edr.crowdstrike.cannon.processrollup2

  • edr.crowdstrike.cannon.processrollup2stats

  • edr.crowdstrike.cannon.sensorheartbeat

  • edr.crowdstrike.cannon.syntheticprocessrollup2

Check more info about these parsers

Cylance PROTECT 

  • edr.cylance.app
  • edr.cylance.audit
  • edr.cylance.device
  • edr.cylance.memory
  • edr.cylance.script
  • edr.cylance.threats

Check more info about these parsers

Fireeye Endpoint Detection & Response

  • edr.fireeye.alerts

Check more info about these parsers

Minerva Labs

Minerva Labs anti-evasion platform

  • edr.minervalabs

Check more info about these parsers

ObserveIT Insider Threat Detection

  • edr.observeit.events

Palo Alto Cortex XDR

  • edr.paloalto.cortex_xdr
  • edr.paloalto.cortex_xdr_agent

Check more info about these parsers

image2021-6-15_11-33-45.png

Symantec Endpoint Detection & Response

  • edr.symantec.events