Events pertaining to HTTP proxies, servers, or other L7 network devices.
These events belong to the http_proxy or http_server metaclass.
The clientvars, httpmethod, referrer, statuscode, uri, and useragent fields are used in Trellix rules and analytics. The domain field is used in intel matching.
Taxonomy | Type | Description |
|---|---|---|
| string | HTTP or other client variables |
| string | Domain name. Typically seen in HTTP, DNS, or authentication requests. May be extracted from |
| string | HTTP method (such as |
| string | HTTP or other referrer |
| integer | HTTP code (such as |
| string | Malicious resource URI. May be extracted from |
| string | HTTP client user agent |