XDR_DATA Fields ↗
This section lists all of the xdr_data dataset fields in alphabetical order.
| Field Name | Data Type | Description |
|---|---|---|
| _insert_time | INTEGER | System field: The time the data entry was added to the system. |
| _product | STRING | System field: The data product as ingested from the data collector. |
| _raw_json | RECORD | System field: All raw data as ingested from the data collector in a JSON format. |
| _raw_log | STRING | System field: All raw data as ingested from the data collector in a text format. |
| _time | INTEGER | System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database. |
| _vendor | STRING | System field: The data vendor as ingested from the data collector. |
| action_threat_ids | STRING | Threat IDs |
| additional_info | STRING | Additional information for any event that occurred (GlobalProtect). |
| agent_content_version | STRING | The agent content version. |
| agent_external_ip | STRING | External IP of the agent reporting this event. |
| agent_host_boot_time | INTEGER | Last time this host was started in epoch time. |
| agent_hostname | STRING | Hostname of the agent. |
| agent_id | STRING | A unique identifier per agent. |
| agent_install_type | INTEGER | <p>Agent installation type with the following possible values: 0 - Standard agent 1 - Virtual Desktop Infrastructure (VDI) instance 2 - Virtual Desktop Infrastructure (VDI) golden image 4 - Temporary session 5 - Light agent</p> |
| agent_interface_map | RECORD | Agent interface maps (IPs and Mac). |
| agent_ip_addresses | STRING | All IPv4 interface addresses. |
| agent_ip_addresses_v6 | STRING | All IPv6 interface addresses. |
| agent_is_vdi | BOOLEAN | Indicates whether or not the agent is a VDI agent. |
| agent_mac_addresses | RECORD | Mac addresses assigned to all interfaces for this agent. |
| agent_os_sub_type | STRING | A lengthier description of the operating system (OS) type. |
| agent_os_type | INTEGER | <p>Windows = 1 MacOS = 2 Linux = 4</p> |
| agent_request_time | ||
| agent_session_start_time | INTEGER | Indicates when the agent was started. |
| agent_status_component | STRING | Gives the name of the endpoint detection and response (EDR) filter that was updated. |
| agent_version | STRING | The agent version. |
| associated_event_ids | STRING | |
| associated_mac | STRING | Associated mac addresses. |
| association_strength | INTEGER | <p>Indicates whether an agent_id includes an associated value using this enum mapping: 10 IP Address 20 MAC 30 Hardware ID 35 Collector ID 40 Agent ID 45 Collector Event Data 50 Event Data</p> |
| auth_client | STRING | The client-side host. |
| auth_client_type | STRING | Type of device that the client operated from, such as a computer. |
| auth_correlation_id | STRING | Identifies events from seperate sessions that occurred together as part of an operation. |
| auth_domain | STRING | User-side domain name. |
| auth_identity | STRING | Client-side identification. |
| auth_identity_display_name | STRING | Display name of the authentication actor. |
| auth_identity_id | STRING | Identity \ Principal ID |
| auth_identity_sid | STRING | Identity SID |
| auth_is_interactive | BOOLEAN | <p>True: Interactive sign-ins, where a user manually signs in using their username and password. False: Non-interactive sign-ins, such as a service-to-service authentication.</p> |
| auth_method | STRING | Auth method, such as a publickey and password. |
| auth_mfa_needed | BOOLEAN | Indicates whether or not a Multi-factor authentication (MFA) is required. |
| auth_normalized_user | RECORD | Normalized user information. |
| auth_outcome | STRING | Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE". |
| auth_outcome_reason | STRING | Event success status description. |
| auth_server | STRING | Server-side host. |
| auth_service | STRING | Authentication service name. |
| auth_service_sid | STRING | Service SID |
| auth_target | STRING | Authentication target host. |
| auth_target_id | STRING | Target \ Resource ID |
| azure_ad_resource_display_name | STRING | Display name of the Azure AD resource (authentication server). |
| azure_ad_resource_id | STRING | Resource ID |
| azure_ad_resource_tenant_id | STRING | Resource tenant ID. |
| azure_authentication_info | ||
| azure_authentication_risk_info | ||
| backtrace_identities | RECORD | |
| cef_device_product | STRING | Extracted CEF product. |
| cef_device_vendor | STRING | Extracted CEF vendor. |
| cef_device_version | STRING | Extracted CEF device version. |
| cef_extension | STRING | Extracted CEF extension. |
| cef_severity | STRING | Extracted CEF severity. |
| cef_signature_id | STRING | Extracted CEF signature ID. |
| cef_version | INTEGER | Extracted CEF version. |
| checkpoint_vpn_data | ||
| cisco_vpn_data | ||
| client_version | INTEGER | The endpoints GlobalProtect version. |
| client_version_str | ||
| clipboard_data_size | INTEGER | Size of data. |
| clipboard_data_type | INTEGER | CF_UNICODETEXT, CF_BITMAP |
| clipboard_source_iid | STRING | IID of the source process of the copied data. |
| cloud_entity | RECORD | Cloud provider information on the source IP of the activity. |
| customerId | STRING | Extracted customer ID. |
| device_id | RECORD | |
| device_name | ||
| dfe_labels | STRING | Story label |
| directionality_strength | ||
| dns_query_items | RECORD | List of all the request items (name and type). |
| dns_query_name | STRING | DNS request name. |
| dns_query_name_domain_randomness | RECORD | Domain randomness score. |
| dns_query_type | STRING | DNS query type. |
| dns_reply_code | STRING | <p>0 -> No error 1 -> Format Error 2 -> Server Failure 3 -> Non-Existent Domain 4 -> Not Implemented 5 -> Query Refused 6 -> Name Exists when it should not 7 -> RR Set Exists when it should not 8 -> RR Set that should exist does not 9 -> Server Not Authoritative for zone 10 -> Name not contained in zone 16 -> Bad OPT Version 16 -> TSIG Signature Failure 17 -> Key not recognized 18 -> Signature out of time window 19 -> Bad TKEY Mode 20 -> Duplicate key name 21 -> Algorithm not supported 22 -> Bad Truncation</p> |
| dns_reply_codes | RECORD | DNS reply codes for the DNS query. |
| dns_resolutions | RECORD | DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item. |
| dst_action_as_data | RECORD | ASN data from the destination of the network activity. |
| dst_action_boot_time | INTEGER | Destination computer boot time in ms since the last epoch time. |
| dst_action_country | STRING | Destination country of the action. |
| dst_action_external_hostname | STRING | The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action_remote_ip. |
| dst_action_external_hostname_domain_randomness | RECORD | Domain randomness score. |
| dst_action_external_port | INTEGER | <p>The port Cortex XDR/XSIAM connects to. For a proxy connection, this value can differ from the action_remote_port.</p> |
| dst_action_location | RECORD | Geolocation information of the destination IP. |
| dst_action_powered_off | BOOLEAN | <p>True, if the computer is powered off, such as suspend or hibernate. False, otherwise.</p> |
| dst_action_url_category | STRING | Next-Generation Firewall (NGFW) URL category. |
| dst_action_user_agent | STRING | The user agent used by an actor to perform an action. |
| dst_action_user_is_local_session | BOOLEAN | Indicates whether or not the user login from a remote computer or locally. |
| dst_action_user_session_id | INTEGER | Session ID of the action. |
| dst_action_user_status | INTEGER | Same as the event sub-type. |
| dst_action_user_status_sid | STRING | Security identifier (SID) of the user. |
| dst_action_username | STRING | Name of the destination user. |
| dst_agent_content_version | STRING | Agent content version. |
| dst_agent_external_ip | STRING | The IP that the destination agent reported this data. |
| dst_agent_host_boot_time | INTEGER | Host boot time in epoch time. |
| dst_agent_hostname | STRING | Agent hostname |
| dst_agent_id | STRING | Agent ID |
| dst_agent_install_type | INTEGER | <p>Type of agent installation: 0 - Standard agent 1 - VDI instance 2 - VDI golden image 4 - Temporary session 5 - Light agent</p> |
| dst_agent_interface_map | RECORD | Agent interface maps (IPs and Mac) |
| dst_agent_ip_addresses | STRING | Agent IPv4 addresses. |
| dst_agent_ip_addresses_v6 | STRING | Agent IPv6 addresses. |
| dst_agent_is_vdi | BOOLEAN | Indicates whether or not the agent is a VDI installation. |
| dst_agent_os_sub_type | STRING | A lengthier description of the Operating System (OS) type. |
| dst_agent_os_type | INTEGER | <p>Agent Operating System types: Windows = 1 MacOS = 2 Linux = 4</p> |
| dst_agent_request_time | ||
| dst_agent_session_start_time | INTEGER | When the agent was started. |
| dst_agent_status_component | STRING | |
| dst_agent_version | STRING | Agent version |
| dst_associated_mac | STRING | Associated MAC address. |
| dst_association_strength | INTEGER | <p>Specifies whether an agent_id includes an associated value, using this enum mapping: 0 = No association 10 = IP Address 15 = Kerberos 20 = MAC 30 = Hardware ID 35 = Collector ID 40 = Agent ID 45 = Collector Event Data 50 = Event Data</p> |
| dst_causality_actor_primary_normalized_user | RECORD | A normalized user for the causality chain. |
| dst_cloud_entity | RECORD | Cloud provider information on the destination IP of the activity. |
| dst_device_id | ||
| dst_event_utc_diff_minutes | INTEGER | The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone. |
| dst_host_metadata_domain | STRING | Domain of the host. |
| dst_host_metadata_hostname | STRING | |
| Hostname | ||
| dst_host_metadata_interface_map | RECORD | Agent interface maps (IPs and Mac) |
| dst_is_internal_ip | BOOLEAN | Indicates whether or not the source IP is outside the private range. |
| dst_mac | STRING | MAC address |
| dst_manifest_file_version | INTEGER | |
| dst_tcp_flags | INTEGER | TCP flags |
| dst_trapsId | STRING | DEPRECATED |
| dst_ttl | INTEGER | The closest time-to-live (TTL) preceding / following the sensor. |
| dst_user_id | STRING | <p>Windows: Primary user token of the executed binary. Unix: Effective UID of the executed binary.</p> |
| dst_xdr_pro_lite | BOOLEAN | Indicates whether or not the destination agent is running XDR Pro (not XTH). |
| dynamic_event_int_map | RECORD | DEPRECATED |
| dynamic_event_string_map | RECORD | Same as dynamic_event_int_map, only those are string values. |
| event_address_code_symbol | STRING | |
| event_address_mapped_image_path | STRING | Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in. |
| event_allocation_base_shellcode_buffer | STRING | Hexlified buffer of shellcode at the base of the allocation of the event associated buffer. |
| event_call_region_base_address | INTEGER | Call region base address related to the event. |
| event_call_region_shellcode_buffer | STRING | Hexlified buffer of shellcode at the call region. |
| event_causality_mark_of_cain | INTEGER | <p>Indicates whether a security event, such as BTP and static analysis, was raised in this causality. kNotification (1) - A security event has occurred and has NOT been prevented. kPrevention (2) - A security event has occurred but was (partially or fully) prevented.</p> |
| event_direct_syscall_ip_mapped_file_path | STRING | When the event is a direct syscall, this field contains the DLL that the syscall originated from. |
| event_id | STRING | Event identifier |
| event_impersonation_status | INTEGER | <p>This is equivalent to the event_is_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 Impersonated = 1 Not-Impersonated = 2</p> |
| event_invalidity_field | STRING | Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid. |
| event_is_boot_replay | BOOLEAN | A boolean value that is true during the the first replay. |
| event_is_duplicated_replay | BOOLEAN | A boolean value that is true if the event was already sent before and another replay sends this event again. |
| event_is_impersonated | BOOLEAN | Windows: Indicates whether or not the thread performing the event is impersonating. |
| event_is_replay | BOOLEAN | Indicates whether or not the event is part of the system state replay sent when the agent is started. |
| event_is_simulated | BOOLEAN | Indicates whether or not this event was simulated by the TMS. |
| event_page_base_shellcode_buffer | STRING | Hexlified buffer of shellcode at the base of the page of the event associated buffer. |
| event_resolved_stack_trace | STRING | Stack trace related to the event. |
| event_rpc_func_opnum | INTEGER | Integer identifying the function being called. |
| event_rpc_interface_uuid | STRING | UUID identifying the interface. |
| event_rpc_interface_version_major | INTEGER | Major version of the remote procedure call (RPC) interface. |
| event_rpc_interface_version_minor | INTEGER | minor version of the remote procedure call (RPC) interface. |
| event_rpc_protocol | INTEGER | <p>Enum representing the remote procedure call (RPC) protocol: LocalRpc (ALPC port) = 0 Tcp = 1 NamedPipes = 2 Http = 3</p> |
| event_shellcode_address | INTEGER | The address of the shellcode in the usermode callstack. |
| event_source_bitmask | INTEGER | <p>Bitmask of the sources involved in producing the event: Simulated - 0x01 Kernel-Module - 0x02 EBPF - 0x04 Fanotify - 0x08 Path-Resolved - 0x10</p> |
| event_sub_type | INTEGER | <p>This field is updated based on the event type defined in the event_type field. For each event type, there are multiple event sub types. To see the possible values for the event_type and event_sub_type, create an XQL query with a filter stage, which autocompletes the values.</p> |
| event_thread_context | STRING | <p>A string representing a JSON array containing thread specific context. Note: From XDR agent 8.2, this field is only relevant for office macros.</p> |
| event_timestamp | INTEGER | Integer indicating when the event occurred. |
| event_timestamp_original | INTEGER | Event timestamp in epoch time. |
| event_type | INTEGER | <p>A unique identifier of the event type: Process = 1 Network = 2 File = 3 Registry = 4 Injection = 5 LoadImage = 6 UserStatusChange = 7 TimeChange = 8 Thread = 9 Causality = 10 HostStatusChange = 11 AgentStatusChange = 12 InternalStatistics = 13 ProcessHandle = 14 WindowsEventLog = 15 EpmStatus = 16 MetadataChange = 17 SystemCall = 18 Device = 19 HostFirewall = 23</p> |
| event_user_presence | BOOLEAN | <p>Indicates whether or not there was a physical user presence on the machine. Windows: The value is"true" if the user session was unlocked during the event.</p> |
| event_user_presence_status | INTEGER | <p>This is equivalent to the event_user_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 User not present = 1 User present = 2</p> |
| event_user_thread_context_ip | INTEGER | The instruction pointer at the moment the syscall was made. |
| event_user_thread_context_ip_in_native_ntdll | BOOLEAN | Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll. |
| event_user_thread_context_is_heavens_gate | BOOLEAN | Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process. |
| event_user_thread_context_is_stack_pivot | BOOLEAN | Indicates whether or not the RSP in the trapframe was not inside the thread stack limits. |
| event_user_thread_context_sp | INTEGER | The stack pointer at the moment the syscall was made. |
| event_utc_diff_minutes | INTEGER | The difference in minutes of the original timestamp from UTC. |
| event_validity_enum | INTEGER | <p>An enum set by the preprocessor when detecting that an event is invalid: 1 - valid 2 - invalid due to future timestamp field. 3 - invalid due to an "old" timestamp field that exceeds the host's boot time.</p> |
| event_version | INTEGER | Version of the event structure, where each change increases the version. |
| event_versions | INTEGER | Event version for this event. |
| execution_actor_causality_id | STRING | Causality ID of the parent which executed the terminated process instance. |
| execution_actor_instance_id | STRING | Instance ID of the parent which executed the terminated process instance. |
| facility | STRING | |
| file_data | ||
| fw_dst_normalized_user | RECORD | Normalized user information. |
| fw_identities | RECORD | DEPRECATED |
| fw_is_dup_log | INTEGER | |
| fw_log_subtypes | STRING | |
| fw_log_types | STRING | |
| fw_src_normalized_user | RECORD | Normalized user information. |
| fw_time_generated | INTEGER | Equivalent to the event_timestamp. |
| fw_traffic_flags | INTEGER | Protocol traffic flags as seen on the Next-Generation Firewall (NGFW). |
| generatedTime | TIMESTAMP | Equivalent to the event_timestamp. |
| global_protect_data | ||
| hardware_id | STRING | Unique identifier GlobalProtect assigned to the host. |
| host_metadata_domain | STRING | Domain of the host. |
| host_metadata_hostname | STRING | |
| Hostname | ||
| host_metadata_interface_map | RECORD | Agent interface maps (IPs and Mac). |
| http_content_type | STRING | Content-type header of the HTTP traffic. |
| http_data | RECORD | HTTP log data. |
| http_data_is_trimmed | BOOLEAN | Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW). |
| http_method | STRING | <p>0 = UNKNOWN_METHOD 1 = GET 2 = POST 3 = CONNECT 4 = HEAD 5 = PUT 6 = DELETE 7 = OPTIONS</p> |
| http_referer | STRING | HTTP Referer header. |
| http_req_before_method | STRING | |
| http_req_content_type_header | STRING | HTTP content type header. |
| http_req_host_header | STRING | HTTP host header. |
| http_req_referer_header | STRING | HTTP Referer header. |
| http_req_uri | STRING | HTTP request URI. |
| http_req_user_agent_header | STRING | HTTP user agent header. |
| http_rsp_code | INTEGER | HTTP response code. |
| http_rsp_content_type_header | STRING | HTTP response content type header. |
| http_rsp_filename | STRING | HTTP response filename. |
| http_server | STRING | HTTP server |
| http_status_code | INTEGER | HTTP status code. |
| hwnd | INTEGER | The foreground window. |
| icmp_code | INTEGER | ICMP protocol request code. |
| icmp_original_length | INTEGER | Internet Control Message Protocol (ICMP) payload length. |
| icmp_type | INTEGER | ICMP protocol request type. |
| insert_timestamp | TIMESTAMP | Ingestion timestamp |
| is_disintegrated | BOOLEAN | Indicates whether or not the story was disintegrated. |
| is_internal_ip | BOOLEAN | Indicates whether or not the source IP is outside the private range. |
| krb_tgs_data | RECORD | Kerberos Ticket Granting Service (TGS) log data. |
| krb_tgt_data | RECORD | Kerberos Ticket Granting Service (TGS) log data. |
| ldap_data | RECORD | LDAP log data. |
| login_data | RECORD | Windows Event Log login data. |
| login_data_dst_normalized_user | RECORD | Destination user CIE resolution information. |
| login_data_dst_outbound_normalized_user | RECORD | Destination outbound user DSS resolution information. |
| login_data_src_normalized_user | RECORD | Source user CIE resolution information. |
| non_standard_dport | INTEGER | This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic |
| ntlm_auth_data | RECORD | NTLM log data. |
| one_login_data | ||
| other_json | DEPRECATED | |
| packet | STRING | <p>Packet payload excluding TCP/IP header. Only valid for event_sub_type = 17 (raw_data)</p> |
| related_alerts | ||
| serverTime | TIMESTAMP | Timestamp of the event displayed on the server side. |
| ssl_data | RECORD | SSL log data. |
| ssl_req_chello_sni_sample | STRING | SNI domain obtained from SSL protocol parsing. |
| sso_debug_data | STRING | Okta debug info, which includes protocol informaiton, URIs, and more. |
| sso_display_message | STRING | Single Sign-on (SSO) event description. |
| sso_event_type | INTEGER | Single Sign-On (SSO) event type as obtained by the original SSO provider. |
| sso_severity | STRING | Severity as reported: DEBUG, INFO, WARN, ERROR |
| story_id | STRING | ID of the story. |
| story_id_original | DEPRECATED | |
| story_publish_timestamp | INTEGER | Story publishing timestamp in epoch time. |
| story_version | FLOAT | Story version |
| syscall_action_etw_based | BOOLEAN | Indicates whether or not the syscall collected is from Windows ETW. |
| syscall_action_int_params | STRING | Integer parameters from syscalls in a JSON format. |
| syscall_action_stack_ptr | STRING | |
| syscall_action_string_params | STRING | String parameters from syscalls in a JSON format. |
| tcp_flags | INTEGER | TCP Flags |
| title | STRING | Title of top_level_hwnd. |
| top_level_hwnd | INTEGER | The top level window of the foreground window. |
| trapsId | STRING | DEPRECATED |
| ttl | INTEGER | IP Protocol time-to-live (TTL) obtained from the source. |
| tunnel_type | STRING | The type of tunnel. |
| uri | STRING | Threat URI |
| user_generic_value1 | INTEGER | <p>A bitmap that can be set in the YAML. The first bit indicates whether an operation is in the GUI or not.</p> |
| user_generic_value2 | INTEGER | <p>An integer that can be set in the YAML. It is used to indicate Yara rule IDs for windows web shells.</p> |
| user_id | STRING | <p>Windows: User SID Unix: UID</p> |
| uuid | STRING | Equivalent to the 'event_id'. |
| vendor | STRING | Log vendor |
| vpn_event_description | STRING | The name of the GlobalProtect event. |
| vpn_server | STRING | VPN server name or IP. |
| vpn_service | STRING | VPN service name. |
| xdr_pro_lite | BOOLEAN | Indicates whether or not the agent is XDRProNG and sends fewer events. |
| zip_id | STRING | DEPRECATED |
| zscaler_vpn_data |