Classes in the Helix Enterprise taxonomy represent types of events or log sources. For example:
A synthetic event created by an intel hit appears as class
class:intel_hit.An advisory generated by Trellix analytics appears as
class:analytics.
A class is simply an identifier and can be any string. Helix Enterprise uses a naming scheme of class=<vendor>_<product>. For example, class=palo_alto_http.
Note
Events that are not parsed or have not yet been seen in a Helix Enterprise environment appear as
class:unknown.