Document toolboxDocument toolbox

edr.symantec

Introduction

The tags begin with edr.symantec identify the events generated by Symantec.

Tag structure

The full tag must have 3 levels. The first two are fixed as edr.symantec. The third level identifies the type of events sent.

Product / Services

Tags

Data tables

Product / Services

Tags

Data tables

Symantec Endpoint Detection & Response

edr.symantec.events

edr.symantec.events

For more information, read more about Devo tags.

Table structure

These are the fields displayed in this table:

edr.symantec.events

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

split(hostchain, "=", 0)

hostchain

 

cefVersion

str

 

 

 

embDeviceVendor

str

 

 

 

embDeviceProduct

str

 

 

 

deviceVersion

str

 

 

 

signatureID

str

 

 

 

name

str

 

 

 

severity

str

 

 

 

enviromentID

int8

 

 

 

userEmail

str

 

 

 

securityIncidentFamily

str

 

 

 

securityIncidentProperty

str

 

 

 

deviceType

str

 

 

 

deviceMDMStatus

str

 

 

 

classification

str

 

 

 

deviceExternalId

str

 

 

 

end

timestamp

 

 

 

externalId

str

 

 

 

msg

str

 

 

 

shost

str

 

 

 

src

ip4

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓