Layer: Endpoint
This documentation provides detailed information about all fields available for Data Detection and Response.
| Field Name | Type | Searchable | General Field | Description | Example | Products |
|---|---|---|---|---|---|---|
| aggregatedCount | string | true | - | The number of aggregated events |
|
|
| aggregateFunction | int | true | - | The metric aggregator |
|
Data Detection and Response |
| aggregateUnit | string | true | - | The metric unit | file | Data Detection and Response |
| detectionFileList | dynamic | true | - | The information about the related files | {"fileName": "sample.txt", "edgeId": "00000000-0000-0000-0000-000000000000"} | Data Detection and Response |
| dpt | int | true | Port | The destination port number | - |
|
| dst | string | true |
|
The destination IP address |
|
|
| duration | string | true | - | The detection interval (in milliseconds) | 300000 | Data Detection and Response |
| endpointGUID | string | true | EndpointID | The GUID of the agent which reported the detection |
|
|
| endpointHostName | string | true | EndpointName | The endpoint hostname or node where the event was detected |
|
|
| endpointIp | dynamic | true |
|
The IP address of the endpoint on which the event was detected | 10.10.10.10 |
|
| eventId | string | true | - | The event ID from the logs of each product |
|
|
| eventName | string | true | - | The event type |
|
|
| fileHash | string | true | FileSHA1 | The SHA-1 of the file that triggered the rule or policy |
|
|
| firstSeen | string | true | - | The first time the XDR log appeared | 1657195233000 |
|
| lastSeen | string | true | - | The last time the XDR log appeared | 1657195233000 |
|
| lineageId | string | true | - | The lineage ID |
|
Data Detection and Response |
| logonUsers | dynamic | true | - | The telemetry events that match the Security Analytics Engine filter, and logonUsers stores the logonUsers value of the original events | BHBShortJ |
|
| matchedPolicies | dynamic | true | - | The matched policies of detection records | ['00000000-0000-0000-0000-000000000000'] | Data Detection and Response |
| metaSrcExtra | string | true | - | The meta for identifying the source of events | [{'metaSrcUri': ...] | Data Detection and Response |
| objectFileHash | string | true | - | The cryptographic hash of the target process image or file, with the specific hash algorithm to be determined | 1ca71017d2fa4775253670e1e55e26912bfdc156 | Data Detection and Response |
| objectFileSize | string | true | - | The file size of the object file |
|
|
| objectServiceType | string | true | - | Type of target file |
|
Data Detection and Response |
| objectUri | string | true | - | Path of target file | C://path/of/file.txt | Data Detection and Response |
| objectUser | string | true | UserAccount | The owner name of the target process or the login user name |
|
|
| osName | string | true | - | The host OS name |
|
|
| osVer | string | true | - | The OS version | 11 |
|
| policyIds | string | true | - | The Ids of DDR’s data policy | 11111111-1111-1111-1111-111111111111 | Data Detection and Response |
| ruleIdStr | string | true | - | The rule ID | 0000000-0000-0000-0000-000000000000 | Data Detection and Response |
| ruleName | string | true | - | The name of the rule that triggered the event |
|
|
| spt | int | true | Port | The source port number |
|
|
| src | string | true |
|
The source address |
|
|
| srcFileHash | string | true | - | The cryptographic hash of the source process image or file, with the specific hash algorithm to be determined. | 1ca71017d2fa4775253670e1e55e26912bfdc156 | Data Detection and Response |
| srcFileSize | string | true | - | The file size of the source file |
|
|
| srcServiceType | string | true | - | Type of source file |
|
Data Detection and Response |
| srcUri | string | true | - | Path of source file | C://path/of/file.txt | Data Detection and Response |
| srcUser | string | true | - | The owner name of the source process or the login user name |
|
Data Detection and Response |
| uuids | dynamic | true | - | The UUIDs of detection records | ['00000000-0000-0000-0000-000000000000'] | Data Detection and Response |
Generated by XDR Common Schema Public Doc Generator V2