The following table describes the JSON fields and values used for Endpoint Security servers.
Field | Description | Event Type | Release |
|---|---|---|---|
msg | Only the normal format is supported. | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
product | Product name | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
_id | Identifier | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
hostname | Hostname of the infected machine | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
ip | IP address of the infected machine | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
containment_state | Whether the infected machine has been contained | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
os | Name of the target OS | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
agent_id | Agent identifier | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
agent_version | Agent version | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
resolution | Valid values are active_threat (resolution=alert and resolution=partial_block), alert, block, and partial_block. | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
event_id | Event identifier | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
enabled | True for active; false for false-positive | indicator-presence indicator-executed | 3.5 |
operator | A mapping between a field and a value | indicator-presence indicator-executed | 3.5 |
token | Name of test | indicator-presence indicator-executed | 3.5 |
type | Data type | indicator-presence indicator-executed | 3.5 |
value | Data value | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
negate | The negate operation that negates the condition. | indicator-presence | 3.5 |
event_at | Time an event occurred | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
matched_at | Match detection time | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
reported_at | Match reported time | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
source | Source of alert. Valid values are "IOC" (indicator of compromise), "EXD" (exploit detection), and "MAL" (malware alert). | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
matched_source_alerts | Number of source alerts found | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
event_type | Primary event type for this condition (based on the first test) | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
fileWriteEvent/timestamp | Time when a file write event occurred | indicator-presence | 3.5 |
fileWriteEvent/drive | The drive where a file write event occurred | indicator-presence | 3.5 |
fileWriteEvent/id | File write event identifier | indicator-presence | 3.5 |
fileWriteEvent/closed | Time when the file was closed | indicator-presence | 3.5 |
fileWriteEvent/pid | Process identifier | indicator-presence | 3.5 |
fileWriteEvent/filePath | Path of file that was written to | indicator-presence | 3.5 |
fileWriteEvent/fileName | Name of file that was written to | indicator-presence | 3.5 |
fileWriteEvent/lowestFileOffsetSeen | The beginning position, in bytes, observed during the write operation. The raw data is in decimal. Redline shows the data in hexadecimal. The lowest offset of a file from its beginning is 0. | indicator-presence | 3.5 |
fileWriteEvent/textAtLowestOffset | Up to 64 bytes of plaintext observed starting at the lowest offset seen during a write operation. | indicator-presence | 3.5 |
fileWriteEvent/dataAtLowestOffset | Up to 64 bytes of base64-encoded data observed starting at the lowest seen during a write operation. | indicator-presence | 3.5 |
fileWriteEvent/process | Process name of the file write event. | indicator-presence | 3.5 |
fileWriteEvent/md5 | MD5 hash value of file | indicator-presence | 3.5 |
fileWriteEvent/writes | Number of times the file was written to | indicator-presence | 3.5 |
fileWriteEvent/size | Size of the file written to | indicator-presence | 3.5 |
fileWriteEvent/fileExtension | Extension of file written to | indicator-presence | 3.5 |
fileWriteEvent/fullPath | Full path of file written to | indicator-presence | 3.5 |
fileWriteEvent/numBytesSeenWritten | Number of bytes that were written | indicator-presence | 3.5 |
uuid | Unique identifier | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
version | Version | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
appliance-id | Appliance identifier | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
appliance | Appliance name | indicator-presence indicator-executed exploit-blocked exploit-detected | 3.5 |
regKeyEvent/path | Path of registry key event | indicator-executed | 3.5 |
regKeyEvent/value | Value of registry key event | indicator-executed | 3.5 |
regKeyEvent/hive | Hive of the registry event | indicator-executed | 3.5 |
regKeyEvent/KeyPath | Path of registry key | indicator-executed | 3.5 |
regKeyEvent/eventType | Event type | indicator-executed | 3.5 |
regKeyEvent/timestamp | Time stamp of registry key event | indicator-executed | 3.5 |
regKeyEvent/valueType | Type of value | indicator-executed | 3.5 |
regKeyEvent/valueName | Name of value | indicator-executed | 3.5 |
regKeyEvent/id | Identifier of the registry key event | indicator-executed | 3.5 |
regKeyEvent/text | Text of the registry key event | indicator-executed | 3.5 |
regKeyEvent/process | Process name of the registry key event | indicator-executed | 3.5 |
regKeyEvent/pid | Process identifier | indicator-executed | 3.5 |
condition | Condition | exploit-blocked exploit-detected | 3.5 |
event_values | Description of event | exploit-blocked | 3.5 |
detail_type | Type of analysis | exploit-blocked exploit-detected | 3.5 |
rules_version | Rules version | exploit-blocked exploit-detected | 3.5 |
engine_version | Engine version | exploit-blocked exploit-detected | 3.5 |
whitelist_version | Whitelist version | exploit-blocked exploit-detected | 3.5 |
name | Operating system name | exploit-blocked exploit-detected | 3.5 |
sp | Service pack | exploit-blocked exploit-detected | 3.5 |
pid | Process identifier | exploit-blocked exploit-detected | 3.5 |
imagepath | Location | exploit-blocked exploit-detected | 3.5 |
md5sum | MD5 hash value | exploit-blocked exploit-detected | 3.5 |
detail_time | Event time | exploit-blocked exploit-detected | 3.5 |
timestamp | Event time | exploit-blocked exploit-detected | 3.5 |
MESSAGE | Message reported | exploit-blocked exploit-detected | 3.5 |
analysis-id | Analysis identifier | exploit-blocked exploit-detected | 3.5 |
result | Result of action | exploit-blocked | 3.5 |
ppid | Parent process identifier | exploit-blocked exploit-detected | 3.5 |
eventid | Event identfier | exploit-blocked exploit-detected | 3.5 |
parentname | Parent process name | exploit-blocked exploit-detected | 3.5 |
cmdline | Command line | exploit-blocked exploit-detected | 3.5 |
is_malicious | Whether the exploit is malicious | exploit-blocked exploit-detected | 3.5 |
is_blocked | Whether the exploit is blocked | exploit-blocked exploit-detected | 3.5 |
earliest_detection_time | Earliest detection time of exploit | exploit-detected | 3.5 |
process_id | Process identifier | exploit-detected | 3.5 |
messages | Messages displayed | exploit-detected | 3.5 |
process_name | Name of process | exploit-detected | 3.5 |