HTTP request information

Prev Next

Events pertaining to HTTP proxies, servers, or other L7 network devices.

These events belong to the http_proxy or http_server metaclass.

The clientvars, httpmethod, referrer, statuscode, uri, and useragent fields are used in Trellix rules and analytics. The domain field is used in intel matching.

Taxonomy

Type

Description

clientvars

string

HTTP or other client variables

domain

string

Domain name. Typically seen in HTTP, DNS, or authentication requests. May be extracted from url.

httpmethod

string

HTTP method (such as POST, GET, PUT, PATCH, DELETE)

referrer

string

HTTP or other referrer

statuscode

integer

HTTP code (such as 200, 404, 500) or other status code

uri

string

Malicious resource URI. May be extracted from url.

useragent

string

HTTP client user agent