Layer: Cloud
This documentation provides detailed information about all fields available for Container Security.
| Field Name | Type | Searchable | General Field | Description | Example | Products |
|---|---|---|---|---|---|---|
| act | dynamic | true | - | The actions taken to mitigate the event |
|
|
| actionName | string | true | - | The action being taken |
|
Container Security |
| clusterId | string | true | - | The cluster ID of the container | TestCluster-2HJdImvH6eO1fgTnCBK3xYA7Sph | Container Security |
| clusterId | string | true | - | The cluster ID of the container | ben_eks_test-20k90A3jGa4d3YMYfrdGIgs7g9u | Container Security |
| clusterName | string | true | - | The cluster name of the container | TestCluster | Container Security |
| clusterName | string | true | - | The cluster name of the container | ben_eks_test | Container Security |
| compressedFileName | string | true | FileName | The file name of the compressed file |
|
|
| containerId | string | true | - | The Kubernetes container ID | 7d1e00176d78 | Container Security |
| containerId | string | true | - | The Kubernetes container ID | 4102001853b8 | Container Security |
| containerImage | string | true | - | The Kubernetes container image | debian:latest | Container Security |
| containerImage | string | true | - | The Kubernetes container image | dockerhub.io/ubuntu:latest | Container Security |
| containerImageDigest | string | false | - | The Kubernetes container image digest | sha256:bfe6615d017d1eebe19f349669de58cda36c668ef916e618be78071513c690e5 | Container Security |
| containerImageDigest | string | true | - | The Kubernetes container image digest | sha256:626ffe58f6e7566e00254b638eb7e0f3b11d4da9675088f4781a50ae288f3322 | Container Security |
| containerName | string | true | - | The Kubernetes container name | k8s_democon_longrunl_default_11111111-1111-1111-1111-111111111111_0 | Container Security |
| containerName | string | true | - | The Kubernetes container name | k8s_ubuntu_ubuntu-ds-fp2jk_default_00000000-0000-0000-0000-000000000000_2 | Container Security |
| customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} | Container Security |
| customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} |
|
| customTags | dynamic | true | - | The event tags |
|
|
| detectionType | string | true | - | The detection type |
|
|
| dpt | int | true | Port | The destination port number | - | Container Security |
| dpt | int | true | Port | The destination port |
|
|
| dst | string | true |
|
The destination IP address |
|
Container Security |
| dst | dynamic | true |
|
The destination IP | 10.10.10.10 |
|
| endpointGUID | string | true | EndpointID | The GUID of the agent which reported the detection |
|
|
| endpointHostName | string | false | - | The host name of the container or node |
|
Container Security |
| endpointHostName | string | true | EndpointName | The endpoint hostname or node where the event was detected |
|
|
| eventId | int | true | - | Event type | - | Container Security |
| eventId | string | true | - | The event ID from the logs of each product |
|
|
| eventSubId | int | true | - | The access type |
|
Container Security |
| eventTime | real | true | - | The time the agent detected the event | 1657781088000 | Container Security |
| fileDesc | string | true | - | The file description |
|
|
| fileHashSha256 | string | true | FileSHA2 | The SHA-256 of the file (fileName) |
|
|
| fileOperation | string | true | - | The operation of the file |
|
|
| fileType | string | true | - | The file type of the suspicious file |
|
|
| fullPath | string | true | FileFullPath | The combination of the file path and the file name |
|
|
| isEntity | string | true | - | The current entity (or after change/modification) |
|
|
| k8sNamespace | string | true | - | The Kubernetes namespace of the container | default | Container Security |
| k8sNamespace | string | true | - | The Kubernetes namespace of the container | default | Container Security |
| k8sPodId | string | true | - | The Kubernetes pod ID of the container | 11111111-1111-1111-1111-111111111111 | Container Security |
| k8sPodId | string | true | - | The Kubernetes pod ID of the container |
|
Container Security |
| k8sPodName | string | true | - | The Kubernetes pod name of the container | longrunl | Container Security |
| k8sPodName | string | true | - | The Kubernetes pod name of the container | ubuntu-ds-fp2jk | Container Security |
| malName | string | true | - | The name of the detected malware |
|
|
| malType | string | true | - | The risk type for Network Content Correlation Engine rules |
|
|
| objectFileCreation | string | true | - | The UTC time that the object was created |
|
|
| objectFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the objectFilePath object |
|
|
| objectFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the object (objectFilePath) |
|
|
| objectFileModifiedTime | string | true | - | The time the object file was modified |
|
Container Security |
| objectFileName | string | true | FileName | The object file name |
|
|
| objectFilePath | string | true |
|
The file path of the target process image or target file |
|
Container Security |
| objectFilePath | string | true | FileFullPath | The file path of the target process image or target file |
|
|
| objectFileSize | long | true | - | The object file size |
|
|
| objectUser | string | true | UserAccount | The owner name of the target process or the login user name |
|
Container Security |
| osName | string | false | - | The host operating system name | Linux | Container Security |
| parentCmd | string | true | CLICommand | The command line entry of the parent process |
|
Container Security |
| parentCmd | string | true | CLICommand | The command line of the subject parent process |
|
|
| parentFilePath | string | true |
|
The file path of the parent process |
|
Container Security |
| parentLaunchTime | real | false | - | The time when the parent process was launched |
|
Container Security |
| parentName | string | false | - | The image name of the parent process |
|
Container Security |
| parentName | string | true | - | The image name of the parent process |
|
|
| parentPid | int | true | - | The PID of the parent process |
|
Container Security |
| parentPid | int | true | - | The PID of the parent process | - |
|
| platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} | Container Security |
| platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} |
|
| pname | string | true | - | The internal product ID |
|
|
| policyId | string | false | - | The policy ID | TestPolicy-2HJe25H4GY4upSuNNAG1pci2BIm | Container Security |
| policyId | string | true | - | The policy ID of which the event was detected |
|
|
| policyName | string | false | - | The name of the triggered policy | TestPolicy | Container Security |
| policyName | string | true | - | The name of the triggered policy |
|
|
| principalName | string | true | - | The user principal name used to sign in to the proxy | sample_email@trendmicro.com |
|
| processCmd | string | true | CLICommand | Command line entry of subject process |
|
Container Security |
| processCmd | string | true | CLICommand | The subject process command line |
|
|
| processFilePath | string | true | ProcessFullPath | The file path of the subject process |
|
Container Security |
| processImagePath | string | true | - | The process triggered by the file event |
|
|
| processLaunchTime | real | false | - | The time the subject process was launched |
|
Container Security |
| processName | string | true | ProcessName | The image name of the process that triggered the event |
|
Container Security |
| processName | string | true | ProcessName | The image name of the process that triggered the event |
|
|
| processPid | int | true | - | The PID of the subject process |
|
Container Security |
| processPid | int | true | - | The PID of the subject process | - |
|
| processUser | string | true | UserAccount | The user name of the process or the file creator |
|
|
| proto | string | false | - | The protocol type |
|
Container Security |
| proto | string | true | - | The exploited layer network protocol |
|
|
| pver | string | true | - | The product version |
|
Container Security |
| pver | string | true | - | The product version |
|
|
| rawDataStr | string | false | - | The JSON string that contains additional information |
|
|
| requestDecision | string | true | - | Whether the request was allowed or denied by the authorization system | allow/deny | Container Security |
| resourceCategory | string | true | - | The category of the object | roles | Container Security |
| resourceName | string | true | - | The specific name of the object | pod-reader | Container Security |
| resourceNamespace | string | true | - | The namespace where the referenced resource exists |
|
Container Security |
| respCode | string | true | - | The network protocol response code |
|
|
| ruleIdStr | string | false | - | The rule ID | TM-00000036 | Container Security |
| ruleIdStr | string | true | - | The rule ID | TM-00000043 |
|
| ruleName | string | true | - | The name of the rule that triggered the event |
|
|
| ruleSetId | string | true | - | The rule set ID | AllRules-1zSSZPsDqfqkcOt5vNsD6f383HN | Container Security |
| ruleSetName | string | true | - | The rule set name | AllRules |
|
| ruleType | string | true | - | The access rule type |
|
|
| scanType | string | true | - | The scan type |
|
|
| severity | int | true | - | The severity of the event |
|
|
| sourceType | string | true | - | The source type |
|
|
| spt | int | true | Port | The source port number |
|
Container Security |
| spt | int | true | Port | The source port |
|
|
| src | string | true |
|
The source address |
|
Container Security |
| src | dynamic | true |
|
The source IP | 10.10.10.10 |
|
| srcFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the source file | - | Container Security |
| srcFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the source file | - | Container Security |
| srcFileModifiedTime | string | true | - | The time the source file was modified |
|
Container Security |
| srcFilePath | string | true |
|
The source file path |
|
Container Security |
| srcFileSize | string | true | - | The file size of the source file |
|
Container Security |
| tags | dynamic | true |
|
The detected ID based on the alert filter |
|
|
| userDefinedFields | dynamic | true | - | The user-defined field for custom detection rules | {"message": "There is a shell process running in the container with ID \"1234567890abcdef\"."} | Container Security |
| wasEntity | string | true | - | The entity before change/modification |
|
|
Generated by XDR Common Schema Public Doc Generator V2