Classes

Prev Next

Classes in the Helix Enterprise taxonomy represent types of events or log sources. For example:

  • A synthetic event created by an intel hit appears as class class:intel_hit.

  • An advisory generated by Trellix analytics appears as class:analytics.

A class is simply an identifier and can be any string. Helix Enterprise uses a naming scheme of class=<vendor>_<product>. For example, class=palo_alto_http.

Note

Events that are not parsed or have not yet been seen in a Helix Enterprise environment appear as class:unknown.