.edr.cylance vv7.7.0
Introduction
The tags beginning with edr.cylance identify events generated by Cylance.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as edr.cylance. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
Technology | Brand | Type | Subtype |
---|---|---|---|
edr | cylance | protect |
|
optics |
|
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
edr.cylance.protect.app | edr.cylance.protect.app |
edr.cylance.protect.audit | edr.cylance.protect.audit |
edr.cylance.protect.script | edr.cylance.protect.script |
edr.cylance.protect.device | edr.cylance.protect.device |
edr.cylance.protect.devicecontrol | edr.cylance.protect.devicecontrol |
edr.cylance.protect.threats | edr.cylance.protect.threats |
edr.cylance.protect.memory | edr.cylance.protect.memory |
edr.cylance.optics.process | edr.cylance.optics.process |
edr.cylance.optics.file | edr.cylance.optics.file |
edr.cylance.optics.registry | edr.cylance.optics.registry |
edr.cylance.optics.network | edr.cylance.optics.network |
edr.cylance.optics.memory | edr.cylance.optics.memory |
edr.cylance.optics.dns | edr.cylance.optics.dns |
edr.cylance.optics.log | edr.cylance.optics.log |
edr.cylance.optics.powershell | edr.cylance.optics.powershell |
edr.cylance.optics.wmi | edr.cylance.optics.wmi |
How is the data sent to Devo?
Logs generated by Cylance must be sent to the Devo platform via the Devo Relay to secure communication.
Once your Relay is receiving Syslog messages (in our case through port 13006), the relay will be able to forward these logs to the right Devo tables by configuring the following relay rules:
Log samples
The following are sample logs sent to each of the edr.cylance data tables. Also, find how the information will be parsed in your data table under each sample log.
Extra columns
Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.
We've divided the sample logs into 2 different groups:
edr.cylance.protect
-
edr.cylance.optics
-