edr.trellix
Introduction
The tags begin with edr.trellix
identify the events generated by Trellix.
Tag structure
The full tag must have 4 levels. The first two are fixed as edr.trellix
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
Product / Services | Tags | Data tables |
---|---|---|
Trellix Endpoint Security |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in this table:
edr.trellix.epo.threat
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
|
|
|
|
detectedutc |
| int8(detectedutc_str) = null ? parsedate(detectedutc_str, "YYYY-MM-DD[T]HH:mm:ss.SSSZZ") : timestamp(int8(detectedutc_str)) | detectedutc_str |
|
analyzermac |
|
|
|
|
receivedutc |
| int8(receivedutc_str) = null ? parsedate(receivedutc_str, "YYYY-MM-DD[T]HH:mm:ss.SSSZZ") : timestamp(int8(receivedutc_str)) | receivedutc_str |
|
eventtimelocal |
| int8(eventtimelocal_str) = null ? parsedate(eventtimelocal_str, "YYYY-MM-DD[T]HH:mm:ss.SSSZZ") : timestamp(int8(eventtimelocal_str)) | eventtimelocal_str |
|
sourceipv6 |
|
|
|
|
sourceipv4 |
|
|
|
|
threatseverity |
|
|
|
|
analyzer |
|
|
|
|
tenantid |
|
|
|
|
nodepath |
|
|
|
|
threattype |
|
|
|
|
threateventid |
|
|
|
|
analyzerversion |
|
|
|
|
agentguid |
|
|
|
|
threatactiontaken |
|
|
|
|
threat_name |
|
|
|
|
analyzername |
|
|
|
|
threatcategory |
|
|
|
|
autoguid |
|
|
|
|
targetipv6 |
|
|
|
|
analyzeripv6 |
|
|
|
|
analyzeripv4 |
|
|
|
|
analyzerhostname |
|
|
|
|
targetipv4 |
|
|
|
|
tenantguid |
|
|
|
|
threathandled |
|
|
|
|
id |
|
|
|
|
type |
|
|
|
|
links__self |
|
|
|
|
timestamp |
| timestamp_str |
| |
analyzerdatversion |
|
|
|
|
analyzerengineversion |
|
|
|
|
analyzerdetectionmethod |
|
|
|
|
sourcehostname |
|
|
|
|
sourcemac |
|
|
|
|
sourceusername |
|
|
|
|
sourceprocessname |
|
|
|
|
sourceurl |
|
|
|
|
targethostname |
|
|
|
|
targetmac |
|
|
|
|
targetusername |
|
|
|
|
targetport |
|
|
|
|
targetprotocol |
|
|
|
|
targetprocessname |
|
|
|
|
targetfilename |
|
|
|
|
targethash |
|
|
|
|
sourceprocesshash |
|
|
|
|
sourceprocesssigned |
|
|
|
|
sourceprocesssigner |
|
|
|
|
sourcefilepath |
|
|
|
|
at_devo_environment |
|
|
|
|
at_devo_pulling_id |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |