This section lists all of the xdr\_data dataset fields in alphabetical order.
| Field Name | Data Type | Description |
| --------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| \_insert\_time | INTEGER | System field: The time the data entry was added to the system. |
| \_product | STRING | System field: The data product as ingested from the data collector. |
| \_raw\_json | RECORD | System field: All raw data as ingested from the data collector in a JSON format. |
| \_raw\_log | STRING | System field: All raw data as ingested from the data collector in a text format. |
| \_time | INTEGER | System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database. |
| \_vendor | STRING | System field: The data vendor as ingested from the data collector. |
| action\_threat\_ids | STRING | Threat IDs |
| additional\_info | STRING | Additional information for any event that occurred (GlobalProtect). |
| agent\_content\_version | STRING | The agent content version. |
| agent\_external\_ip | STRING | External IP of the agent reporting this event. |
| agent\_host\_boot\_time | INTEGER | Last time this host was started in epoch time. |
| agent\_hostname | STRING | Hostname of the agent. |
| agent\_id | STRING | A unique identifier per agent. |
| agent\_install\_type | INTEGER | <p>Agent installation type with the following possible values:<br>0 - Standard agent<br>1 - Virtual Desktop Infrastructure (VDI) instance<br>2 - Virtual Desktop Infrastructure (VDI) golden image<br>4 - Temporary session<br>5 - Light agent</p> |
| agent\_interface\_map | RECORD | Agent interface maps (IPs and Mac). |
| agent\_ip\_addresses | STRING | All IPv4 interface addresses. |
| agent\_ip\_addresses\_v6 | STRING | All IPv6 interface addresses. |
| agent\_is\_vdi | BOOLEAN | Indicates whether or not the agent is a VDI agent. |
| agent\_mac\_addresses | RECORD | Mac addresses assigned to all interfaces for this agent. |
| agent\_os\_sub\_type | STRING | A lengthier description of the operating system (OS) type. |
| agent\_os\_type | INTEGER | <p>Windows = 1<br>MacOS = 2<br>Linux = 4</p> |
| agent\_request\_time | | |
| agent\_session\_start\_time | INTEGER | Indicates when the agent was started. |
| agent\_status\_component | STRING | Gives the name of the endpoint detection and response (EDR) filter that was updated. |
| agent\_version | STRING | The agent version. |
| associated\_event\_ids | STRING | |
| associated\_mac | STRING | Associated mac addresses. |
| association\_strength | INTEGER | <p>Indicates whether an agent_id includes an associated value using this enum mapping:<br>10 IP Address<br>20 MAC<br>30 Hardware ID<br>35 Collector ID<br>40 Agent ID<br>45 Collector Event Data<br>50 Event Data</p> |
| auth\_client | STRING | The client-side host. |
| auth\_client\_type | STRING | Type of device that the client operated from, such as a computer. |
| auth\_correlation\_id | STRING | Identifies events from seperate sessions that occurred together as part of an operation. |
| auth\_domain | STRING | User-side domain name. |
| auth\_identity | STRING | Client-side identification. |
| auth\_identity\_display\_name | STRING | Display name of the authentication actor. |
| auth\_identity\_id | STRING | Identity \ Principal ID |
| auth\_identity\_sid | STRING | Identity SID |
| auth\_is\_interactive | BOOLEAN | <p>True: Interactive sign-ins, where a user manually signs in using their username and password.<br>False: Non-interactive sign-ins, such as a service-to-service authentication.</p> |
| auth\_method | STRING | Auth method, such as a publickey and password. |
| auth\_mfa\_needed | BOOLEAN | Indicates whether or not a Multi-factor authentication (MFA) is required. |
| auth\_normalized\_user | RECORD | Normalized user information. |
| auth\_outcome | STRING | Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE". |
| auth\_outcome\_reason | STRING | Event success status description. |
| auth\_server | STRING | Server-side host. |
| auth\_service | STRING | Authentication service name. |
| auth\_service\_sid | STRING | Service SID |
| auth\_target | STRING | Authentication target host. |
| auth\_target\_id | STRING | Target \ Resource ID |
| azure\_ad\_resource\_display\_name | STRING | Display name of the Azure AD resource (authentication server). |
| azure\_ad\_resource\_id | STRING | Resource ID |
| azure\_ad\_resource\_tenant\_id | STRING | Resource tenant ID. |
| azure\_authentication\_info | | |
| azure\_authentication\_risk\_info | | |
| backtrace\_identities | RECORD | |
| cef\_device\_product | STRING | Extracted CEF product. |
| cef\_device\_vendor | STRING | Extracted CEF vendor. |
| cef\_device\_version | STRING | Extracted CEF device version. |
| cef\_extension | STRING | Extracted CEF extension. |
| cef\_severity | STRING | Extracted CEF severity. |
| cef\_signature\_id | STRING | Extracted CEF signature ID. |
| cef\_version | INTEGER | Extracted CEF version. |
| checkpoint\_vpn\_data | | |
| cisco\_vpn\_data | | |
| client\_version | INTEGER | The endpoints GlobalProtect version. |
| client\_version\_str | | |
| clipboard\_data\_size | INTEGER | Size of data. |
| clipboard\_data\_type | INTEGER | CF\_UNICODETEXT, CF\_BITMAP |
| clipboard\_source\_iid | STRING | IID of the source process of the copied data. |
| cloud\_entity | RECORD | Cloud provider information on the source IP of the activity. |
| customerId | STRING | Extracted customer ID. |
| device\_id | RECORD | |
| device\_name | | |
| dfe\_labels | STRING | Story label |
| directionality\_strength | | |
| dns\_query\_items | RECORD | List of all the request items (name and type). |
| dns\_query\_name | STRING | DNS request name. |
| dns\_query\_name\_domain\_randomness | RECORD | Domain randomness score. |
| dns\_query\_type | STRING | DNS query type. |
| dns\_reply\_code | STRING | <p>0 -> No error<br>1 -> Format Error<br>2 -> Server Failure<br>3 -> Non-Existent Domain<br>4 -> Not Implemented<br>5 -> Query Refused<br>6 -> Name Exists when it should not<br>7 -> RR Set Exists when it should not<br>8 -> RR Set that should exist does not<br>9 -> Server Not Authoritative for zone<br>10 -> Name not contained in zone<br>16 -> Bad OPT Version<br>16 -> TSIG Signature Failure<br>17 -> Key not recognized<br>18 -> Signature out of time window<br>19 -> Bad TKEY Mode<br>20 -> Duplicate key name<br>21 -> Algorithm not supported<br>22 -> Bad Truncation</p> |
| dns\_reply\_codes | RECORD | DNS reply codes for the DNS query. |
| dns\_resolutions | RECORD | DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item. |
| dst\_action\_as\_data | RECORD | ASN data from the destination of the network activity. |
| dst\_action\_boot\_time | INTEGER | Destination computer boot time in ms since the last epoch time. |
| dst\_action\_country | STRING | Destination country of the action. |
| dst\_action\_external\_hostname | STRING | The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action\_remote\_ip. |
| dst\_action\_external\_hostname\_domain\_randomness | RECORD | Domain randomness score. |
| dst\_action\_external\_port | INTEGER | <p>The port Cortex XDR/XSIAM connects to.<br>For a proxy connection, this value can differ from the action_remote_port.</p> |
| dst\_action\_location | RECORD | Geolocation information of the destination IP. |
| dst\_action\_powered\_off | BOOLEAN | <p>True, if the computer is powered off, such as suspend or hibernate.<br>False, otherwise.</p> |
| dst\_action\_url\_category | STRING | Next-Generation Firewall (NGFW) URL category. |
| dst\_action\_user\_agent | STRING | The user agent used by an actor to perform an action. |
| dst\_action\_user\_is\_local\_session | BOOLEAN | Indicates whether or not the user login from a remote computer or locally. |
| dst\_action\_user\_session\_id | INTEGER | Session ID of the action. |
| dst\_action\_user\_status | INTEGER | Same as the event sub-type. |
| dst\_action\_user\_status\_sid | STRING | Security identifier (SID) of the user. |
| dst\_action\_username | STRING | Name of the destination user. |
| dst\_agent\_content\_version | STRING | Agent content version. |
| dst\_agent\_external\_ip | STRING | The IP that the destination agent reported this data. |
| dst\_agent\_host\_boot\_time | INTEGER | Host boot time in epoch time. |
| dst\_agent\_hostname | STRING | Agent hostname |
| dst\_agent\_id | STRING | Agent ID |
| dst\_agent\_install\_type | INTEGER | <p>Type of agent installation: 0 - Standard agent<br>1 - VDI instance<br>2 - VDI golden image<br>4 - Temporary session<br>5 - Light agent</p> |
| dst\_agent\_interface\_map | RECORD | Agent interface maps (IPs and Mac) |
| dst\_agent\_ip\_addresses | STRING | Agent IPv4 addresses. |
| dst\_agent\_ip\_addresses\_v6 | STRING | Agent IPv6 addresses. |
| dst\_agent\_is\_vdi | BOOLEAN | Indicates whether or not the agent is a VDI installation. |
| dst\_agent\_os\_sub\_type | STRING | A lengthier description of the Operating System (OS) type. |
| dst\_agent\_os\_type | INTEGER | <p>Agent Operating System types: Windows = 1<br>MacOS = 2<br>Linux = 4</p> |
| dst\_agent\_request\_time | | |
| dst\_agent\_session\_start\_time | INTEGER | When the agent was started. |
| dst\_agent\_status\_component | STRING | |
| dst\_agent\_version | STRING | Agent version |
| dst\_associated\_mac | STRING | Associated MAC address. |
| dst\_association\_strength | INTEGER | <p>Specifies whether an agent_id includes an associated value, using this enum mapping:<br>0 = No association<br>10 = IP Address<br>15 = Kerberos<br>20 = MAC<br>30 = Hardware ID<br>35 = Collector ID<br>40 = Agent ID<br>45 = Collector Event Data<br>50 = Event Data</p> |
| dst\_causality\_actor\_primary\_normalized\_user | RECORD | A normalized user for the causality chain. |
| dst\_cloud\_entity | RECORD | Cloud provider information on the destination IP of the activity. |
| dst\_device\_id | | |
| dst\_event\_utc\_diff\_minutes | INTEGER | The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone. |
| dst\_host\_metadata\_domain | STRING | Domain of the host. |
| dst\_host\_metadata\_hostname | STRING | |
| Hostname | | |
| dst\_host\_metadata\_interface\_map | RECORD | Agent interface maps (IPs and Mac) |
| dst\_is\_internal\_ip | BOOLEAN | Indicates whether or not the source IP is outside the private range. |
| dst\_mac | STRING | MAC address |
| dst\_manifest\_file\_version | INTEGER | |
| dst\_tcp\_flags | INTEGER | TCP flags |
| dst\_trapsId | STRING | DEPRECATED |
| dst\_ttl | INTEGER | The closest time-to-live (TTL) preceding / following the sensor. |
| dst\_user\_id | STRING | <p>Windows: Primary user token of the executed binary.<br>Unix: Effective UID of the executed binary.</p> |
| dst\_xdr\_pro\_lite | BOOLEAN | Indicates whether or not the destination agent is running XDR Pro (not XTH). |
| dynamic\_event\_int\_map | RECORD | DEPRECATED |
| dynamic\_event\_string\_map | RECORD | Same as dynamic\_event\_int\_map, only those are string values. |
| event\_address\_code\_symbol | STRING | |
| event\_address\_mapped\_image\_path | STRING | Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in. |
| event\_allocation\_base\_shellcode\_buffer | STRING | Hexlified buffer of shellcode at the base of the allocation of the event associated buffer. |
| event\_call\_region\_base\_address | INTEGER | Call region base address related to the event. |
| event\_call\_region\_shellcode\_buffer | STRING | Hexlified buffer of shellcode at the call region. |
| event\_causality\_mark\_of\_cain | INTEGER | <p>Indicates whether a security event, such as BTP and static analysis, was raised in this causality.<br>kNotification (1) - A security event has occurred and has NOT been prevented.<br>kPrevention (2) - A security event has occurred but was (partially or fully) prevented.</p> |
| event\_direct\_syscall\_ip\_mapped\_file\_path | STRING | When the event is a direct syscall, this field contains the DLL that the syscall originated from. |
| event\_id | STRING | Event identifier |
| event\_impersonation\_status | INTEGER | <p>This is equivalent to the event_is_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.<br>Unknown = 0<br>Impersonated = 1<br>Not-Impersonated = 2</p> |
| event\_invalidity\_field | STRING | Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid. |
| event\_is\_boot\_replay | BOOLEAN | A boolean value that is true during the the first replay. |
| event\_is\_duplicated\_replay | BOOLEAN | A boolean value that is true if the event was already sent before and another replay sends this event again. |
| event\_is\_impersonated | BOOLEAN | Windows: Indicates whether or not the thread performing the event is impersonating. |
| event\_is\_replay | BOOLEAN | Indicates whether or not the event is part of the system state replay sent when the agent is started. |
| event\_is\_simulated | BOOLEAN | Indicates whether or not this event was simulated by the TMS. |
| event\_page\_base\_shellcode\_buffer | STRING | Hexlified buffer of shellcode at the base of the page of the event associated buffer. |
| event\_resolved\_stack\_trace | STRING | Stack trace related to the event. |
| event\_rpc\_func\_opnum | INTEGER | Integer identifying the function being called. |
| event\_rpc\_interface\_uuid | STRING | UUID identifying the interface. |
| event\_rpc\_interface\_version\_major | INTEGER | Major version of the remote procedure call (RPC) interface. |
| event\_rpc\_interface\_version\_minor | INTEGER | minor version of the remote procedure call (RPC) interface. |
| event\_rpc\_protocol | INTEGER | <p>Enum representing the remote procedure call (RPC) protocol:<br>LocalRpc (ALPC port) = 0<br>Tcp = 1<br>NamedPipes = 2<br>Http = 3</p> |
| event\_shellcode\_address | INTEGER | The address of the shellcode in the usermode callstack. |
| event\_source\_bitmask | INTEGER | <p>Bitmask of the sources involved in producing the event:<br>Simulated - 0x01<br>Kernel-Module - 0x02<br>EBPF - 0x04<br>Fanotify - 0x08<br>Path-Resolved - 0x10</p> |
| event\_sub\_type | INTEGER | <p>This field is updated based on the event type defined in the event_type field. For each event type, there are multiple event sub types.<br>To see the possible values for the event_type and event_sub_type, create an XQL query with a filter stage, which autocompletes the values.</p> |
| event\_thread\_context | STRING | <p>A string representing a JSON array containing thread specific context.<br>Note: From XDR agent 8.2, this field is only relevant for office macros.</p> |
| event\_timestamp | INTEGER | Integer indicating when the event occurred. |
| event\_timestamp\_original | INTEGER | Event timestamp in epoch time. |
| event\_type | INTEGER | <p>A unique identifier of the event type:<br>Process = 1<br>Network = 2<br>File = 3<br>Registry = 4<br>Injection = 5<br>LoadImage = 6<br>UserStatusChange = 7<br>TimeChange = 8<br>Thread = 9<br>Causality = 10<br>HostStatusChange = 11<br>AgentStatusChange = 12<br>InternalStatistics = 13<br>ProcessHandle = 14<br>WindowsEventLog = 15<br>EpmStatus = 16<br>MetadataChange = 17<br>SystemCall = 18<br>Device = 19<br>HostFirewall = 23</p> |
| event\_user\_presence | BOOLEAN | <p>Indicates whether or not there was a physical user presence on the machine.<br>Windows: The value is"true" if the user session was unlocked during the event.</p> |
| event\_user\_presence\_status | INTEGER | <p>This is equivalent to the event_user_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.<br>Unknown = 0<br>User not present = 1<br>User present = 2</p> |
| event\_user\_thread\_context\_ip | INTEGER | The instruction pointer at the moment the syscall was made. |
| event\_user\_thread\_context\_ip\_in\_native\_ntdll | BOOLEAN | Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll. |
| event\_user\_thread\_context\_is\_heavens\_gate | BOOLEAN | Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process. |
| event\_user\_thread\_context\_is\_stack\_pivot | BOOLEAN | Indicates whether or not the RSP in the trapframe was not inside the thread stack limits. |
| event\_user\_thread\_context\_sp | INTEGER | The stack pointer at the moment the syscall was made. |
| event\_utc\_diff\_minutes | INTEGER | The difference in minutes of the original timestamp from UTC. |
| event\_validity\_enum | INTEGER | <p>An enum set by the preprocessor when detecting that an event is invalid:<br>1 - valid<br>2 - invalid due to future timestamp field.<br>3 - invalid due to an "old" timestamp field that exceeds the host's boot time.</p> |
| event\_version | INTEGER | Version of the event structure, where each change increases the version. |
| event\_versions | INTEGER | Event version for this event. |
| execution\_actor\_causality\_id | STRING | Causality ID of the parent which executed the terminated process instance. |
| execution\_actor\_instance\_id | STRING | Instance ID of the parent which executed the terminated process instance. |
| facility | STRING | |
| file\_data | | |
| fw\_dst\_normalized\_user | RECORD | Normalized user information. |
| fw\_identities | RECORD | DEPRECATED |
| fw\_is\_dup\_log | INTEGER | |
| fw\_log\_subtypes | STRING | |
| fw\_log\_types | STRING | |
| fw\_src\_normalized\_user | RECORD | Normalized user information. |
| fw\_time\_generated | INTEGER | Equivalent to the event\_timestamp. |
| fw\_traffic\_flags | INTEGER | Protocol traffic flags as seen on the Next-Generation Firewall (NGFW). |
| generatedTime | TIMESTAMP | Equivalent to the event\_timestamp. |
| global\_protect\_data | | |
| hardware\_id | STRING | Unique identifier GlobalProtect assigned to the host. |
| host\_metadata\_domain | STRING | Domain of the host. |
| host\_metadata\_hostname | STRING | |
| Hostname | | |
| host\_metadata\_interface\_map | RECORD | Agent interface maps (IPs and Mac). |
| http\_content\_type | STRING | Content-type header of the HTTP traffic. |
| http\_data | RECORD | HTTP log data. |
| http\_data\_is\_trimmed | BOOLEAN | Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW). |
| http\_method | STRING | <p>0 = UNKNOWN_METHOD<br>1 = GET<br>2 = POST<br>3 = CONNECT<br>4 = HEAD<br>5 = PUT<br>6 = DELETE<br>7 = OPTIONS</p> |
| http\_referer | STRING | HTTP Referer header. |
| http\_req\_before\_method | STRING | |
| http\_req\_content\_type\_header | STRING | HTTP content type header. |
| http\_req\_host\_header | STRING | HTTP host header. |
| http\_req\_referer\_header | STRING | HTTP Referer header. |
| http\_req\_uri | STRING | HTTP request URI. |
| http\_req\_user\_agent\_header | STRING | HTTP user agent header. |
| http\_rsp\_code | INTEGER | HTTP response code. |
| http\_rsp\_content\_type\_header | STRING | HTTP response content type header. |
| http\_rsp\_filename | STRING | HTTP response filename. |
| http\_server | STRING | HTTP server |
| http\_status\_code | INTEGER | HTTP status code. |
| hwnd | INTEGER | The foreground window. |
| icmp\_code | INTEGER | ICMP protocol request code. |
| icmp\_original\_length | INTEGER | Internet Control Message Protocol (ICMP) payload length. |
| icmp\_type | INTEGER | ICMP protocol request type. |
| insert\_timestamp | TIMESTAMP | Ingestion timestamp |
| is\_disintegrated | BOOLEAN | Indicates whether or not the story was disintegrated. |
| is\_internal\_ip | BOOLEAN | Indicates whether or not the source IP is outside the private range. |
| krb\_tgs\_data | RECORD | Kerberos Ticket Granting Service (TGS) log data. |
| krb\_tgt\_data | RECORD | Kerberos Ticket Granting Service (TGS) log data. |
| ldap\_data | RECORD | LDAP log data. |
| login\_data | RECORD | Windows Event Log login data. |
| login\_data\_dst\_normalized\_user | RECORD | Destination user CIE resolution information. |
| login\_data\_dst\_outbound\_normalized\_user | RECORD | Destination outbound user DSS resolution information. |
| login\_data\_src\_normalized\_user | RECORD | Source user CIE resolution information. |
| non\_standard\_dport | INTEGER | This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic |
| ntlm\_auth\_data | RECORD | NTLM log data. |
| one\_login\_data | | |
| other\_json | DEPRECATED | |
| packet | STRING | <p>Packet payload excluding TCP/IP header.<br>Only valid for event_sub_type = 17 (raw_data)</p> |
| related\_alerts | | |
| serverTime | TIMESTAMP | Timestamp of the event displayed on the server side. |
| ssl\_data | RECORD | SSL log data. |
| ssl\_req\_chello\_sni\_sample | STRING | SNI domain obtained from SSL protocol parsing. |
| sso\_debug\_data | STRING | Okta debug info, which includes protocol informaiton, URIs, and more. |
| sso\_display\_message | STRING | Single Sign-on (SSO) event description. |
| sso\_event\_type | INTEGER | Single Sign-On (SSO) event type as obtained by the original SSO provider. |
| sso\_severity | STRING | Severity as reported: DEBUG, INFO, WARN, ERROR |
| story\_id | STRING | ID of the story. |
| story\_id\_original | DEPRECATED | |
| story\_publish\_timestamp | INTEGER | Story publishing timestamp in epoch time. |
| story\_version | FLOAT | Story version |
| syscall\_action\_etw\_based | BOOLEAN | Indicates whether or not the syscall collected is from Windows ETW. |
| syscall\_action\_int\_params | STRING | Integer parameters from syscalls in a JSON format. |
| syscall\_action\_stack\_ptr | STRING | |
| syscall\_action\_string\_params | STRING | String parameters from syscalls in a JSON format. |
| tcp\_flags | INTEGER | TCP Flags |
| title | STRING | Title of top\_level\_hwnd. |
| top\_level\_hwnd | INTEGER | The top level window of the foreground window. |
| trapsId | STRING | DEPRECATED |
| ttl | INTEGER | IP Protocol time-to-live (TTL) obtained from the source. |
| tunnel\_type | STRING | The type of tunnel. |
| uri | STRING | Threat URI |
| user\_generic\_value1 | INTEGER | <p>A bitmap that can be set in the YAML.<br>The first bit indicates whether an operation is in the GUI or not.</p> |
| user\_generic\_value2 | INTEGER | <p>An integer that can be set in the YAML.<br>It is used to indicate Yara rule IDs for windows web shells.</p> |
| user\_id | STRING | <p>Windows: User SID<br>Unix: UID</p> |
| uuid | STRING | Equivalent to the 'event\_id'. |
| vendor | STRING | Log vendor |
| vpn\_event\_description | STRING | The name of the GlobalProtect event. |
| vpn\_server | STRING | VPN server name or IP. |
| vpn\_service | STRING | VPN service name. |
| xdr\_pro\_lite | BOOLEAN | Indicates whether or not the agent is XDRProNG and sends fewer events. |
| zip\_id | STRING | DEPRECATED |
| zscaler\_vpn\_data | | |