Most managed products now use a common event format. The fields of this format can be used as columns in the Threat Event Log.
These fields include:
Action Taken — Action that the product took in response to the threat.
Agent GUID — Unique identifier of the agent that forwarded the event.
DAT Version — DAT version on the system that sent the event.
Detecting Product Host Name — Name of the system hosting the detecting product.
Detecting Product ID — ID of the detecting product.
Detecting Product IPv4 Address — IPv4 address of the system hosting the detecting product (if applicable).
Detecting Product IPv6 Address — IPv6 address of the system hosting the detecting product (if applicable).
Detecting Product MAC Address — MAC address of the system hosting the detecting product.
Detecting Product Name — Name of the detecting managed product.
Detecting Product Version — Version number of the detecting product.
Engine Version — Version number of the detecting product’s engine (if applicable).
Event Category — Category of the event. Possible categories depend on the product.
Event Generated Time (UTC) — Time in Coordinated Universal Time that the event was detected.
Event ID — Unique identifier of the event.
Event Received Time (UTC) — Time in Coordinated Universal Time that ePO - On-prem received the event.
File Path — File path of the system which sent the event.
Host Name — Name of the system which sent the event.
IPv4 Address — IPv4 address of the system which sent the event.
IPv6 Address — IPv6 address of the system which sent the event.
MAC Address — MAC address of the system which sent the event.
Network Protocol — Threat target protocol for network-homed threat classes.
Port Number — Threat target port for network-homed threat classes.
Process Name — Target process name (if applicable).
Server ID — Server ID that sent the event.
Threat Name — Name of the threat.
Threat Source Host Name — System name from which the threat originated.
Threat Source IPv4 Address — IPv4 address of the system from which the threat originated.
Threat Source IPv6 Address — IPv6 address of the system from which the threat originated.
Threat Source MAC Address — MAC address of the system from which the threat originated.
Threat Source URL — URL from which the threat originated.
Threat Source User Name — User name from which the threat originated.
Threat Type — Class of the threat.
User Name — Threat source user name or email address.