Document toolboxDocument toolbox

siem.crowdstrike

Introduction

The tags beginning with siem.crowdstrike identify events generated by CrowdStrike.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as siem.crowdstrike. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

CrowdStrike Falcon LogScale

siem.crowdstrike.falcon_logscale.search

siem.crowdstrike.falcon_logscale.search

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

siem.crowdstrike.falcon_logscale.search

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

hostname

str

 

 

type

str

 

 

repo

str

 

 

host

str

 

 

at_id

str

 

 

at_timezone

str

 

 

at_timestamp_nanos

str

 

 

at_timestamp

timestamp

 

 

at_ingesttimestamp

str

 

 

at_rawstring

str

 

 

message

str

rawMessage

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

 

✓