edr.cisco
Introduction
The tags begin with edr.cisco
identify the events generated by Cisco.
Tag structure
The full tag must have 3 levels. The first two are fixed as edr.cisco
. The third level identifies the type of events sent.
Product / Services | Tags | Data tables |
---|---|---|
Cisco Secure Endpoint (Formerly AMP for Endpoints) |
|
|
|
| |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
edr.cisco.amp.computers
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
connector_guid |
|
|
hostname |
|
|
active |
|
|
links_computer |
|
|
links_trajectory |
|
|
links_group |
|
|
connector_version |
|
|
operating_system |
|
|
internal_ips |
|
|
external_ip |
|
|
group_guid |
|
|
install_date |
|
|
network_addresses |
|
|
policy_guid |
|
|
policy_name |
|
|
last_seen |
|
|
faults |
|
|
isolation_available |
|
|
isolation_status |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.cisco.amp.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
id |
|
|
|
|
timestamp |
|
|
|
|
timestamp_nanoseconds |
|
|
|
|
date |
|
|
|
|
event_type |
|
|
|
|
event_type_id |
|
|
|
|
detection |
|
|
|
|
detection_id |
|
|
|
|
connector_guid |
|
|
|
|
group_guids |
|
|
|
|
severity |
|
|
|
|
computer_connector_guid |
|
|
|
|
computer_hostname |
|
|
|
|
computer_external_ip |
|
|
|
|
computer_user |
|
|
|
|
computer_active |
|
|
|
|
computer_network_addresses |
|
|
|
|
computer_network_addresses_ip |
|
|
|
|
computer_network_addresses_ip_str |
| join(computer_network_addresses_ip_values, ',') | computer_network_addresses_ip_values |
|
computer_network_addresses_mac |
|
|
|
|
computer_network_addresses_mac_str |
| join(computer_network_addresses_mac_values, ',') | computer_network_addresses_mac_values |
|
computer_links_computer |
|
|
|
|
computer_links_trajectory |
|
|
|
|
computer_links_group |
|
|
|
|
cloud_ioc_description |
|
|
|
|
cloud_ioc_short_description |
|
|
|
|
file_disposition |
|
|
|
|
file_file_name |
|
|
|
|
file_file_path |
|
|
|
|
file_identity_sha256 |
|
|
|
|
file_identity_sha1 |
|
|
|
|
file_identity_md5 |
|
|
|
|
file_parent_process_id |
|
|
|
|
file_parent_disposition |
|
|
|
|
file_parent_file_name |
|
|
|
|
file_parent_identity_sha256 |
|
|
|
|
file_parent_identity_sha1 |
|
|
|
|
file_parent_identity_md5 |
|
|
|
|
file_attack_details_application |
|
|
|
|
file_attack_details_attacked_module |
|
|
|
|
file_attack_details_base_address |
|
|
|
|
file_attack_details_suspicious_files_str |
| join(file_attack_details_suspicious_files, ',') | file_attack_details_suspicious_files |
|
file_attack_details_indicators |
|
|
|
|
command_line_arguments |
|
|
|
|
tactics_str |
| tactics |
| |
techniques_str |
| techniques |
| |
bp_data__id |
|
|
|
|
bp_data__name |
|
|
|
|
bp_data__type |
|
|
|
|
bp_data__details__matched_activity__events__process_start__cmd_line_str |
| bp_data__details__matched_activity__events__process_start__cmd_line |
| |
bp_data__details__matched_activity__events__process_start__parent_app__name_str |
| bp_data__details__matched_activity__events__process_start__parent_app__name |
| |
bp_data__details__matched_activity__events__process_start__parent_app__path_str |
| bp_data__details__matched_activity__events__process_start__parent_app__path |
| |
bp_data__details__matched_activity__events__process_start__parent_user__domain_str |
| bp_data__details__matched_activity__events__process_start__parent_user__domain |
| |
bp_data__details__matched_activity__events__process_start__parent_user__name_str |
| bp_data__details__matched_activity__events__process_start__parent_user__name |
| |
bp_data__details__matched_activity__events__process_start__parent_user__sid_str |
| bp_data__details__matched_activity__events__process_start__parent_user__sid |
| |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
|
|
edr.cisco.amp.vulnerabilities
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
application |
|
|
version |
|
|
file_filename |
|
|
file_identity_sha256 |
|
|
cves |
|
|
latest_timestamp |
|
|
latest_date |
|
|
groups |
|
|
computers_total_count |
|
|
computers |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |