XDR_DATA Fields

This section lists all of the xdr_data dataset fields in alphabetical order.

Field Name Data Type Description
_insert_time INTEGER System field: The time the data entry was added to the system.
_product STRING System field: The data product as ingested from the data collector.
_raw_json RECORD System field: All raw data as ingested from the data collector in a JSON format.
_raw_log STRING System field: All raw data as ingested from the data collector in a text format.
_time INTEGER System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database.
_vendor STRING System field: The data vendor as ingested from the data collector.
action_threat_ids STRING Threat IDs
additional_info STRING Additional information for any event that occurred (GlobalProtect).
agent_content_version STRING The agent content version.
agent_external_ip STRING External IP of the agent reporting this event.
agent_host_boot_time INTEGER Last time this host was started in epoch time.
agent_hostname STRING Hostname of the agent.
agent_id STRING A unique identifier per agent.
agent_install_type INTEGER <p>Agent installation type with the following possible values:
0 - Standard agent
1 - Virtual Desktop Infrastructure (VDI) instance
2 - Virtual Desktop Infrastructure (VDI) golden image
4 - Temporary session
5 - Light agent</p>
agent_interface_map RECORD Agent interface maps (IPs and Mac).
agent_ip_addresses STRING All IPv4 interface addresses.
agent_ip_addresses_v6 STRING All IPv6 interface addresses.
agent_is_vdi BOOLEAN Indicates whether or not the agent is a VDI agent.
agent_mac_addresses RECORD Mac addresses assigned to all interfaces for this agent.
agent_os_sub_type STRING A lengthier description of the operating system (OS) type.
agent_os_type INTEGER <p>Windows = 1
MacOS = 2
Linux = 4</p>
agent_request_time    
agent_session_start_time INTEGER Indicates when the agent was started.
agent_status_component STRING Gives the name of the endpoint detection and response (EDR) filter that was updated.
agent_version STRING The agent version.
associated_event_ids STRING  
associated_mac STRING Associated mac addresses.
association_strength INTEGER <p>Indicates whether an agent_id includes an associated value using this enum mapping:
10 IP Address
20 MAC
30 Hardware ID
35 Collector ID
40 Agent ID
45 Collector Event Data
50 Event Data</p>
auth_client STRING The client-side host.
auth_client_type STRING Type of device that the client operated from, such as a computer.
auth_correlation_id STRING Identifies events from seperate sessions that occurred together as part of an operation.
auth_domain STRING User-side domain name.
auth_identity STRING Client-side identification.
auth_identity_display_name STRING Display name of the authentication actor.
auth_identity_id STRING Identity \ Principal ID
auth_identity_sid STRING Identity SID
auth_is_interactive BOOLEAN <p>True: Interactive sign-ins, where a user manually signs in using their username and password.
False: Non-interactive sign-ins, such as a service-to-service authentication.</p>
auth_method STRING Auth method, such as a publickey and password.
auth_mfa_needed BOOLEAN Indicates whether or not a Multi-factor authentication (MFA) is required.
auth_normalized_user RECORD Normalized user information.
auth_outcome STRING Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE".
auth_outcome_reason STRING Event success status description.
auth_server STRING Server-side host.
auth_service STRING Authentication service name.
auth_service_sid STRING Service SID
auth_target STRING Authentication target host.
auth_target_id STRING Target \ Resource ID
azure_ad_resource_display_name STRING Display name of the Azure AD resource (authentication server).
azure_ad_resource_id STRING Resource ID
azure_ad_resource_tenant_id STRING Resource tenant ID.
azure_authentication_info    
azure_authentication_risk_info    
backtrace_identities RECORD  
cef_device_product STRING Extracted CEF product.
cef_device_vendor STRING Extracted CEF vendor.
cef_device_version STRING Extracted CEF device version.
cef_extension STRING Extracted CEF extension.
cef_severity STRING Extracted CEF severity.
cef_signature_id STRING Extracted CEF signature ID.
cef_version INTEGER Extracted CEF version.
checkpoint_vpn_data    
cisco_vpn_data    
client_version INTEGER The endpoints GlobalProtect version.
client_version_str    
clipboard_data_size INTEGER Size of data.
clipboard_data_type INTEGER CF_UNICODETEXT, CF_BITMAP
clipboard_source_iid STRING IID of the source process of the copied data.
cloud_entity RECORD Cloud provider information on the source IP of the activity.
customerId STRING Extracted customer ID.
device_id RECORD  
device_name    
dfe_labels STRING Story label
directionality_strength    
dns_query_items RECORD List of all the request items (name and type).
dns_query_name STRING DNS request name.
dns_query_name_domain_randomness RECORD Domain randomness score.
dns_query_type STRING DNS query type.
dns_reply_code STRING <p>0 -> No error
1 -> Format Error
2 -> Server Failure
3 -> Non-Existent Domain
4 -> Not Implemented
5 -> Query Refused
6 -> Name Exists when it should not
7 -> RR Set Exists when it should not
8 -> RR Set that should exist does not
9 -> Server Not Authoritative for zone
10 -> Name not contained in zone
16 -> Bad OPT Version
16 -> TSIG Signature Failure
17 -> Key not recognized
18 -> Signature out of time window
19 -> Bad TKEY Mode
20 -> Duplicate key name
21 -> Algorithm not supported
22 -> Bad Truncation</p>
dns_reply_codes RECORD DNS reply codes for the DNS query.
dns_resolutions RECORD DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item.
dst_action_as_data RECORD ASN data from the destination of the network activity.
dst_action_boot_time INTEGER Destination computer boot time in ms since the last epoch time.
dst_action_country STRING Destination country of the action.
dst_action_external_hostname STRING The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action_remote_ip.
dst_action_external_hostname_domain_randomness RECORD Domain randomness score.
dst_action_external_port INTEGER <p>The port Cortex XDR/XSIAM connects to.
For a proxy connection, this value can differ from the action_remote_port.</p>
dst_action_location RECORD Geolocation information of the destination IP.
dst_action_powered_off BOOLEAN <p>True, if the computer is powered off, such as suspend or hibernate.
False, otherwise.</p>
dst_action_url_category STRING Next-Generation Firewall (NGFW) URL category.
dst_action_user_agent STRING The user agent used by an actor to perform an action.
dst_action_user_is_local_session BOOLEAN Indicates whether or not the user login from a remote computer or locally.
dst_action_user_session_id INTEGER Session ID of the action.
dst_action_user_status INTEGER Same as the event sub-type.
dst_action_user_status_sid STRING Security identifier (SID) of the user.
dst_action_username STRING Name of the destination user.
dst_agent_content_version STRING Agent content version.
dst_agent_external_ip STRING The IP that the destination agent reported this data.
dst_agent_host_boot_time INTEGER Host boot time in epoch time.
dst_agent_hostname STRING Agent hostname
dst_agent_id STRING Agent ID
dst_agent_install_type INTEGER <p>Type of agent installation: 0 - Standard agent
1 - VDI instance
2 - VDI golden image
4 - Temporary session
5 - Light agent</p>
dst_agent_interface_map RECORD Agent interface maps (IPs and Mac)
dst_agent_ip_addresses STRING Agent IPv4 addresses.
dst_agent_ip_addresses_v6 STRING Agent IPv6 addresses.
dst_agent_is_vdi BOOLEAN Indicates whether or not the agent is a VDI installation.
dst_agent_os_sub_type STRING A lengthier description of the Operating System (OS) type.
dst_agent_os_type INTEGER <p>Agent Operating System types: Windows = 1
MacOS = 2
Linux = 4</p>
dst_agent_request_time    
dst_agent_session_start_time INTEGER When the agent was started.
dst_agent_status_component STRING  
dst_agent_version STRING Agent version
dst_associated_mac STRING Associated MAC address.
dst_association_strength INTEGER <p>Specifies whether an agent_id includes an associated value, using this enum mapping:
0 = No association
10 = IP Address
15 = Kerberos
20 = MAC
30 = Hardware ID
35 = Collector ID
40 = Agent ID
45 = Collector Event Data
50 = Event Data</p>
dst_causality_actor_primary_normalized_user RECORD A normalized user for the causality chain.
dst_cloud_entity RECORD Cloud provider information on the destination IP of the activity.
dst_device_id    
dst_event_utc_diff_minutes INTEGER The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone.
dst_host_metadata_domain STRING Domain of the host.
dst_host_metadata_hostname STRING  
Hostname    
dst_host_metadata_interface_map RECORD Agent interface maps (IPs and Mac)
dst_is_internal_ip BOOLEAN Indicates whether or not the source IP is outside the private range.
dst_mac STRING MAC address
dst_manifest_file_version INTEGER  
dst_tcp_flags INTEGER TCP flags
dst_trapsId STRING DEPRECATED
dst_ttl INTEGER The closest time-to-live (TTL) preceding / following the sensor.
dst_user_id STRING <p>Windows: Primary user token of the executed binary.
Unix: Effective UID of the executed binary.</p>
dst_xdr_pro_lite BOOLEAN Indicates whether or not the destination agent is running XDR Pro (not XTH).
dynamic_event_int_map RECORD DEPRECATED
dynamic_event_string_map RECORD Same as dynamic_event_int_map, only those are string values.
event_address_code_symbol STRING  
event_address_mapped_image_path STRING Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in.
event_allocation_base_shellcode_buffer STRING Hexlified buffer of shellcode at the base of the allocation of the event associated buffer.
event_call_region_base_address INTEGER Call region base address related to the event.
event_call_region_shellcode_buffer STRING Hexlified buffer of shellcode at the call region.
event_causality_mark_of_cain INTEGER <p>Indicates whether a security event, such as BTP and static analysis, was raised in this causality.
kNotification (1) - A security event has occurred and has NOT been prevented.
kPrevention (2) - A security event has occurred but was (partially or fully) prevented.</p>
event_direct_syscall_ip_mapped_file_path STRING When the event is a direct syscall, this field contains the DLL that the syscall originated from.
event_id STRING Event identifier
event_impersonation_status INTEGER <p>This is equivalent to the event_is_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.
Unknown = 0
Impersonated = 1
Not-Impersonated = 2</p>
event_invalidity_field STRING Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid.
event_is_boot_replay BOOLEAN A boolean value that is true during the the first replay.
event_is_duplicated_replay BOOLEAN A boolean value that is true if the event was already sent before and another replay sends this event again.
event_is_impersonated BOOLEAN Windows: Indicates whether or not the thread performing the event is impersonating.
event_is_replay BOOLEAN Indicates whether or not the event is part of the system state replay sent when the agent is started.
event_is_simulated BOOLEAN Indicates whether or not this event was simulated by the TMS.
event_page_base_shellcode_buffer STRING Hexlified buffer of shellcode at the base of the page of the event associated buffer.
event_resolved_stack_trace STRING Stack trace related to the event.
event_rpc_func_opnum INTEGER Integer identifying the function being called.
event_rpc_interface_uuid STRING UUID identifying the interface.
event_rpc_interface_version_major INTEGER Major version of the remote procedure call (RPC) interface.
event_rpc_interface_version_minor INTEGER minor version of the remote procedure call (RPC) interface.
event_rpc_protocol INTEGER <p>Enum representing the remote procedure call (RPC) protocol:
LocalRpc (ALPC port) = 0
Tcp = 1
NamedPipes = 2
Http = 3</p>
event_shellcode_address INTEGER The address of the shellcode in the usermode callstack.
event_source_bitmask INTEGER <p>Bitmask of the sources involved in producing the event:
Simulated - 0x01
Kernel-Module - 0x02
EBPF - 0x04
Fanotify - 0x08
Path-Resolved - 0x10</p>
event_sub_type INTEGER <p>This field is updated based on the event type defined in the event_type field. For each event type, there are multiple event sub types.
To see the possible values for the event_type and event_sub_type, create an XQL query with a filter stage, which autocompletes the values.</p>
event_thread_context STRING <p>A string representing a JSON array containing thread specific context.
Note: From XDR agent 8.2, this field is only relevant for office macros.</p>
event_timestamp INTEGER Integer indicating when the event occurred.
event_timestamp_original INTEGER Event timestamp in epoch time.
event_type INTEGER <p>A unique identifier of the event type:
Process = 1
Network = 2
File = 3
Registry = 4
Injection = 5
LoadImage = 6
UserStatusChange = 7
TimeChange = 8
Thread = 9
Causality = 10
HostStatusChange = 11
AgentStatusChange = 12
InternalStatistics = 13
ProcessHandle = 14
WindowsEventLog = 15
EpmStatus = 16
MetadataChange = 17
SystemCall = 18
Device = 19
HostFirewall = 23</p>
event_user_presence BOOLEAN <p>Indicates whether or not there was a physical user presence on the machine.
Windows: The value is"true" if the user session was unlocked during the event.</p>
event_user_presence_status INTEGER <p>This is equivalent to the event_user_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.
Unknown = 0
User not present = 1
User present = 2</p>
event_user_thread_context_ip INTEGER The instruction pointer at the moment the syscall was made.
event_user_thread_context_ip_in_native_ntdll BOOLEAN Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll.
event_user_thread_context_is_heavens_gate BOOLEAN Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process.
event_user_thread_context_is_stack_pivot BOOLEAN Indicates whether or not the RSP in the trapframe was not inside the thread stack limits.
event_user_thread_context_sp INTEGER The stack pointer at the moment the syscall was made.
event_utc_diff_minutes INTEGER The difference in minutes of the original timestamp from UTC.
event_validity_enum INTEGER <p>An enum set by the preprocessor when detecting that an event is invalid:
1 - valid
2 - invalid due to future timestamp field.
3 - invalid due to an "old" timestamp field that exceeds the host's boot time.</p>
event_version INTEGER Version of the event structure, where each change increases the version.
event_versions INTEGER Event version for this event.
execution_actor_causality_id STRING Causality ID of the parent which executed the terminated process instance.
execution_actor_instance_id STRING Instance ID of the parent which executed the terminated process instance.
facility STRING  
file_data    
fw_dst_normalized_user RECORD Normalized user information.
fw_identities RECORD DEPRECATED
fw_is_dup_log INTEGER  
fw_log_subtypes STRING  
fw_log_types STRING  
fw_src_normalized_user RECORD Normalized user information.
fw_time_generated INTEGER Equivalent to the event_timestamp.
fw_traffic_flags INTEGER Protocol traffic flags as seen on the Next-Generation Firewall (NGFW).
generatedTime TIMESTAMP Equivalent to the event_timestamp.
global_protect_data    
hardware_id STRING Unique identifier GlobalProtect assigned to the host.
host_metadata_domain STRING Domain of the host.
host_metadata_hostname STRING  
Hostname    
host_metadata_interface_map RECORD Agent interface maps (IPs and Mac).
http_content_type STRING Content-type header of the HTTP traffic.
http_data RECORD HTTP log data.
http_data_is_trimmed BOOLEAN Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW).
http_method STRING <p>0 = UNKNOWN_METHOD
1 = GET
2 = POST
3 = CONNECT
4 = HEAD
5 = PUT
6 = DELETE
7 = OPTIONS</p>
http_referer STRING HTTP Referer header.
http_req_before_method STRING  
http_req_content_type_header STRING HTTP content type header.
http_req_host_header STRING HTTP host header.
http_req_referer_header STRING HTTP Referer header.
http_req_uri STRING HTTP request URI.
http_req_user_agent_header STRING HTTP user agent header.
http_rsp_code INTEGER HTTP response code.
http_rsp_content_type_header STRING HTTP response content type header.
http_rsp_filename STRING HTTP response filename.
http_server STRING HTTP server
http_status_code INTEGER HTTP status code.
hwnd INTEGER The foreground window.
icmp_code INTEGER ICMP protocol request code.
icmp_original_length INTEGER Internet Control Message Protocol (ICMP) payload length.
icmp_type INTEGER ICMP protocol request type.
insert_timestamp TIMESTAMP Ingestion timestamp
is_disintegrated BOOLEAN Indicates whether or not the story was disintegrated.
is_internal_ip BOOLEAN Indicates whether or not the source IP is outside the private range.
krb_tgs_data RECORD Kerberos Ticket Granting Service (TGS) log data.
krb_tgt_data RECORD Kerberos Ticket Granting Service (TGS) log data.
ldap_data RECORD LDAP log data.
login_data RECORD Windows Event Log login data.
login_data_dst_normalized_user RECORD Destination user CIE resolution information.
login_data_dst_outbound_normalized_user RECORD Destination outbound user DSS resolution information.
login_data_src_normalized_user RECORD Source user CIE resolution information.
non_standard_dport INTEGER This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic
ntlm_auth_data RECORD NTLM log data.
one_login_data    
other_json DEPRECATED  
packet STRING <p>Packet payload excluding TCP/IP header.
Only valid for event_sub_type = 17 (raw_data)</p>
related_alerts    
serverTime TIMESTAMP Timestamp of the event displayed on the server side.
ssl_data RECORD SSL log data.
ssl_req_chello_sni_sample STRING SNI domain obtained from SSL protocol parsing.
sso_debug_data STRING Okta debug info, which includes protocol informaiton, URIs, and more.
sso_display_message STRING Single Sign-on (SSO) event description.
sso_event_type INTEGER Single Sign-On (SSO) event type as obtained by the original SSO provider.
sso_severity STRING Severity as reported: DEBUG, INFO, WARN, ERROR
story_id STRING ID of the story.
story_id_original DEPRECATED  
story_publish_timestamp INTEGER Story publishing timestamp in epoch time.
story_version FLOAT Story version
syscall_action_etw_based BOOLEAN Indicates whether or not the syscall collected is from Windows ETW.
syscall_action_int_params STRING Integer parameters from syscalls in a JSON format.
syscall_action_stack_ptr STRING  
syscall_action_string_params STRING String parameters from syscalls in a JSON format.
tcp_flags INTEGER TCP Flags
title STRING Title of top_level_hwnd.
top_level_hwnd INTEGER The top level window of the foreground window.
trapsId STRING DEPRECATED
ttl INTEGER IP Protocol time-to-live (TTL) obtained from the source.
tunnel_type STRING The type of tunnel.
uri STRING Threat URI
user_generic_value1 INTEGER <p>A bitmap that can be set in the YAML.
The first bit indicates whether an operation is in the GUI or not.</p>
user_generic_value2 INTEGER <p>An integer that can be set in the YAML.
It is used to indicate Yara rule IDs for windows web shells.</p>
user_id STRING <p>Windows: User SID
Unix: UID</p>
uuid STRING Equivalent to the 'event_id'.
vendor STRING Log vendor
vpn_event_description STRING The name of the GlobalProtect event.
vpn_server STRING VPN server name or IP.
vpn_service STRING VPN service name.
xdr_pro_lite BOOLEAN Indicates whether or not the agent is XDRProNG and sends fewer events.
zip_id STRING DEPRECATED
zscaler_vpn_data