edr.symantec
Introduction
The tags begin with edr.symantec
identify the events generated by Symantec.
Tag structure
The full tag must have 3 levels. The first two are fixed as edr.symantec
. The third level identifies the type of events sent.
Product / Services | Tags | Data tables |
---|---|---|
Symantec Endpoint Detection & Response |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in this table:
edr.symantec.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| split(hostchain, "=", 0) | hostchain | Â |
cefVersion |
| Â | Â | Â |
embDeviceVendor |
| Â | Â | Â |
embDeviceProduct |
| Â | Â | Â |
deviceVersion |
| Â | Â | Â |
signatureID |
| Â | Â | Â |
name |
| Â | Â | Â |
severity |
| Â | Â | Â |
enviromentID |
| Â | Â | Â |
userEmail |
| Â | Â | Â |
securityIncidentFamily |
| Â | Â | Â |
securityIncidentProperty |
| Â | Â | Â |
deviceType |
| Â | Â | Â |
deviceMDMStatus |
| Â | Â | Â |
classification |
| Â | Â | Â |
deviceExternalId |
| Â | Â | Â |
end |
| Â | Â | Â |
externalId |
| Â | Â | Â |
msg |
| Â | Â | Â |
shost |
| Â | Â | Â |
src |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |