Skip to content

This document shows the fields supported by each provider and operation.

query_cloud_resource_inventory

FieldCrowdStrike Cloud SecurityMicrosoft Defender for CloudPalo Alto Networks Cortex Cloud SecurityWiz Cloud Security[MOCK] CrowdStrike Cloud SecurityType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.namestring
cloud.account.typestring
cloud.account.type_idnumber
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
custom_fields.cloud_account_cloud_providerstring
custom_fields.cloud_account_external_idstring
custom_fields.cloud_account_idstring
custom_fields.cloud_platformstring
custom_fields.external_idstring
custom_fields.native_typestring
custom_fields.provider_unique_idstring
custom_fields.tags[].keystring
custom_fields.tags[].valuestring
custom_fields.wiz_idstring
device.created_timetimestamp
device.created_time_dtstring
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.groups[].namestring
device.groups[].typestring
device.groups[].uidstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.modified_timetimestamp
device.modified_time_dtstring
device.namestring
device.regionstring
device.typestring
device.type_idnumber
device.uidstring
device.uid_altstring
end_timetimestamp
end_time_dtstring
enrichments[].data.benchmark_versionsunknown
enrichments[].data.controlsunknown
enrichments[].data.controls[].benchmarks[].idstring
enrichments[].data.controls[].benchmarks[].namestring
enrichments[].data.controls[].benchmarks[].versionstring
enrichments[].data.controls[].frameworkstring
enrichments[].data.controls[].namestring
enrichments[].data.controls[].typestring
enrichments[].data.controls[].versionstring
enrichments[].data.ioa_countsnumber
enrichments[].data.iom_countsnumber
enrichments[].data.legacy_policy_ids[]number
enrichments[].data.rulesunknown
enrichments[].data.rules[]string
enrichments[].descstring
enrichments[].namestring
enrichments[].providerstring
enrichments[].typestring
enrichments[].valuestring
messagestring
metadata.product.feature.namestring
metadata.product.vendor_namestring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
regionstring
resources[].data.cloud_account_cloud_providerstring
resources[].data.cloud_account_external_idstring
resources[].data.cloud_platformstring
resources[].data.external_idstring
resources[].data.native_typestring
resources[].data.provider_unique_idstring
resources[].data.statusstring
resources[].data.tags[].keystring
resources[].data.tags[].valuestring
resources[].data.wiz_idstring
resources[].group.namestring
resources[].group.uidstring
resources[].labels[]string
resources[].last_seen_timetimestamp
resources[].last_seen_time_dtstring
resources[].namestring
resources[].regionstring
resources[].tags[].namestring
resources[].tags[].valuestring
resources[].typestring
resources[].uidstring
severitystring
severity_idnumber
start_timetimestamp
start_time_dtstring
statusstring
status_codestring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber

query_compliance_findings

FieldAWS Cloud SecurityAWS EventBridge SQSCrowdStrike Cloud SecurityMicrosoft Defender for CloudPalo Alto Networks Cortex Cloud SecurityWiz Cloud Security[MOCK] CrowdStrike Cloud SecurityType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
compliance.assessments[].descstring
compliance.assessments[].meets_criteriaboolean
compliance.assessments[].namestring
compliance.controlstring
compliance.control_parameters[].namestring
compliance.control_parameters[].values[]string
compliance.requirements[]string
compliance.standards[]string
compliance.statusstring
compliance.status_codestring
compliance.status_idnumber
countnumber
custom_fields.finding_namestring
custom_fields.raw_analyzed_atstring
custom_fields.raw_first_seen_atstring
custom_fields.raw_resource_cloud_platformstring
custom_fields.raw_resultstring
custom_fields.raw_statusstring
custom_fields.raw_updated_atstring
custom_fields.resource_native_typestring
custom_fields.resource_typestring
custom_fields.rule_idstring
custom_fields.rule_namestring
custom_fields.rule_short_idstring
custom_fields.security_category_names[]string
custom_fields.security_framework_ids[]string
custom_fields.security_framework_names[]string
custom_fields.security_subcategories[].category.framework.idstring
custom_fields.security_subcategories[].category.framework.namestring
custom_fields.security_subcategories[].category.idstring
custom_fields.security_subcategories[].category.namestring
custom_fields.security_subcategories[].idstring
custom_fields.security_subcategories[].titlestring
custom_fields.security_subcategory_ids[]string
device.descstring
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.hw_info.chassisstring
device.hw_info.serial_numberstring
device.instance_uidstring
device.ipstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.macstring
device.modified_timetimestamp
device.modified_time_dtstring
device.namestring
device.network_statusstring
device.network_status_idnumber
device.org.namestring
device.org.uidstring
device.os.buildstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
device.zonestring
finding_info.analytic.categorystring
finding_info.analytic.namestring
finding_info.analytic.type_idnumber
finding_info.analytic.uidstring
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.descstring
finding_info.first_seen_timetimestamp
finding_info.first_seen_time_dtstring
finding_info.last_seen_timetimestamp
finding_info.last_seen_time_dtstring
finding_info.modified_timetimestamp
finding_info.modified_time_dtstring
finding_info.product_uidstring
finding_info.titlestring
finding_info.types[]string
finding_info.uidstring
messagestring
metadata.correlation_uidstring
metadata.event_codestring
metadata.extensions[].namestring
metadata.extensions[].uidstring
metadata.extensions[].versionstring
metadata.labels[]string
metadata.log_providerstring
metadata.loggers[].namestring
metadata.loggers[].versionstring
metadata.product.namestring
metadata.product.uidstring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.profiles[]string
metadata.uidstring
metadata.versionstring
remediation.descstring
remediation.references[]string
resource.namestring
resource.regionstring
resource.typestring
resource.uidstring
resources[].cloud_partitionstring
resources[].owner.account.uidstring
resources[].regionstring
resources[].typestring
resources[].uidstring
severitystring
severity_idnumber
start_timetimestamp
start_time_dtstring
statusstring
status_codestring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber
vendor_attributes.severitystring
vendor_attributes.severity_idnumber

query_events

FieldAWS Cloud SecurityUpwind Cloud SecurityType
activity_idnumber
activity_namestring
actor.idstring
actor.namestring
actor.typestring
actor.type_idnumber
actor.uidstring
actor.uid_altstring
api.operationstring
api.request.uidstring
api.service.namestring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.type_idnumber
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
device.namestring
device.regionstring
device.type_idnumber
http_request.user_agentstring
messagestring
metadata.event_codestring
metadata.labels[]string
metadata.product.namestring
metadata.product.vendor_namestring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
parameters.AuthenticationMethodstring
parameters.CipherSuitestring
parameters.Hoststring
parameters.SSEAppliedstring
parameters.SignatureVersionstring
parameters.associationIdstring
parameters.bucketNamestring
parameters.bytesTransferredInnumber
parameters.bytesTransferredOutnumber
parameters.executionResult.errorCodestring
parameters.executionResult.executionDatestring
parameters.executionResult.executionSummarystring
parameters.executionResult.statusstring
parameters.instanceIdstring
parameters.keystring
parameters.x-amz-aclstring
parameters.x-amz-id-2string
parameters.x-amz-server-side-encryption[]string
severitystring
severity_idnumber
src_endpoint.ipstring
statusstring
status_idnumber
timenumber
time_dtstring
tls.cipher_suitestring
tls.versionstring
type_namestring
type_uidnumber
web_resources[].labels[]string
web_resources[].namestring
web_resources[].uidstring

query_ioms

FieldCrowdStrike Cloud SecurityPalo Alto Networks Cortex Cloud Security[MOCK] CrowdStrike Cloud SecurityType
activity_idnumber
activity_namestring
actor.authorizations[].policy.descstring
actor.authorizations[].policy.namestring
actor.authorizations[].policy.uidstring
actor.user.has_mfaboolean
actor.user.namestring
api.operationstring
api.service.namestring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.namestring
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
compliance.controlstring
compliance.standards[]string
compliance.statusstring
compliance.status_idnumber
countnumber
device.type_idnumber
device.uidstring
finding_info.analytic.categorystring
finding_info.analytic.namestring
finding_info.analytic.type_idnumber
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.descstring
finding_info.first_seen_timetimestamp
finding_info.titlestring
finding_info.types[]string
finding_info.uidstring
messagestring
metadata.correlation_uidstring
metadata.product.feature.namestring
metadata.product.namestring
metadata.product.url_stringstring
metadata.product.vendor_namestring
metadata.uidstring
metadata.versionstring
remediation.descstring
resource.typestring
resource.uidstring
resources[].data.Creation Datestring
resources[].data.Password Enabledstring
resources[].data.Password Last Changedstring
resources[].data.Password Last Usedstring
resources[].data.Userstring
resources[].data.User Arnstring
resources[].namestring
resources[].owner.namestring
resources[].owner.uidstring
resources[].typestring
resources[].uidstring
severitystring
severity_idnumber
start_timetimestamp
statusstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber

query_threats

FieldAWS Cloud SecurityAWS EventBridge SQSMicrosoft Defender for CloudUpwind Cloud SecurityWiz Cloud SecurityType
activity_idnumber
activity_namestring
actor.user.namestring
actor.user.typestring
actor.user.uidstring
api.operationstring
api.response.errorstring
api.service.namestring
attacks[].tactic.namestring
attacks[].tactic.uidstring
attacks[].technique.namestring
attacks[].technique.uidstring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.namestring
cloud.account.typestring
cloud.account.type_idnumber
cloud.account.uidstring
cloud.cloud_partitionstring
cloud.project_uidstring
cloud.providerstring
cloud.regionstring
countnumber
device.hostnamestring
device.namestring
device.regionstring
device.typestring
device.type_idnumber
device.uidstring
evidences[].data.entityTypestring
evidences[].data.resourceIdstring
evidences[].data.resourceNamestring
evidences[].data.resourceTypestring
evidences[].device.domainstring
evidences[].device.hostnamestring
evidences[].device.type_idnumber
evidences[].file.hashes[].algorithmstring
evidences[].file.hashes[].algorithm_idnumber
evidences[].file.hashes[].valuestring
evidences[].file.namestring
evidences[].file.pathstring
evidences[].file.type_idnumber
evidences[].user.account.namestring
evidences[].user.account.typestring
evidences[].user.domainstring
evidences[].user.namestring
finding_info.analytic.typestring
finding_info.analytic.type_idnumber
finding_info.analytic.uidstring
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.descstring
finding_info.first_seen_timetimestamp
finding_info.first_seen_time_dtstring
finding_info.last_seen_timetimestamp
finding_info.last_seen_time_dtstring
finding_info.modified_timetimestamp
finding_info.modified_time_dtstring
finding_info.product.uidstring
finding_info.titlestring
finding_info.types[]string
finding_info.uidstring
finding_info.uid_altstring
malware[].classification_ids[]number
malware[].files[].hashes[].algorithmstring
malware[].files[].hashes[].algorithm_idnumber
malware[].files[].hashes[].valuestring
malware[].files[].namestring
malware[].files[].pathstring
malware[].files[].typestring
malware[].files[].type_idnumber
malware[].files[].volumestring
malware[].namestring
malware[].num_infectednumber
malware[].severitystring
malware[].severity_idnumber
malware_scan_info.end_timetimestamp
malware_scan_info.end_time_dtstring
malware_scan_info.num_filesnumber
malware_scan_info.num_infectednumber
malware_scan_info.num_volumesnumber
malware_scan_info.sizenumber
malware_scan_info.start_timetimestamp
malware_scan_info.start_time_dtstring
malware_scan_info.typestring
malware_scan_info.type_idnumber
malware_scan_info.uidstring
malware_scan_info.unique_malware_countnumber
messagestring
metadata.event_codestring
metadata.log_providerstring
metadata.product.feature.namestring
metadata.product.namestring
metadata.product.uidstring
metadata.product.vendor_namestring
metadata.profiles[]string
metadata.uidstring
metadata.versionstring
observables[].namestring
observables[].typestring
observables[].type_idnumber
observables[].valuestring
raw_datastring
remediation.descstring
remediation.references[]string
resources[].cloud_partitionstring
resources[].data.availability_zonestring
resources[].data.device_namestring
resources[].data.effective_permissionstring
resources[].data.encryption_typestring
resources[].data.iam_instance_profile.arnstring
resources[].data.iam_instance_profile.idstring
resources[].data.image_descriptionstring
resources[].data.image_idstring
resources[].data.instance_idstring
resources[].data.instance_statestring
resources[].data.instance_typestring
resources[].data.kms_key_arnstring
resources[].data.launch_timetimestamp
resources[].data.launch_time_dtstring
resources[].data.network_interfaces[].network_interface_idstring
resources[].data.network_interfaces[].private_dns_namestring
resources[].data.network_interfaces[].private_ip_addressstring
resources[].data.network_interfaces[].private_ip_addresses[].private_dns_namestring
resources[].data.network_interfaces[].private_ip_addresses[].private_ip_addressstring
resources[].data.network_interfaces[].public_dns_namestring
resources[].data.network_interfaces[].public_ipstring
resources[].data.network_interfaces[].security_groups[].group_idstring
resources[].data.network_interfaces[].security_groups[].group_namestring
resources[].data.network_interfaces[].subnet_idstring
resources[].data.network_interfaces[].vpc_idstring
resources[].data.owner_idstring
resources[].data.resource_typestring
resources[].data.snapshot_arnstring
resources[].data.tags[].keystring
resources[].data.tags[].valuestring
resources[].data.uidstring
resources[].data.volume_arnstring
resources[].data.volume_size_in_gbnumber
resources[].data.volume_typestring
resources[].data.wiz_idstring
resources[].namestring
resources[].owner.account.typestring
resources[].owner.account.type_idnumber
resources[].owner.account.uidstring
resources[].regionstring
resources[].tags[].namestring
resources[].tags[].valuestring
resources[].typestring
resources[].uidstring
severitystring
severity_idnumber
src_endpoint.autonomous_system.namestring
src_endpoint.autonomous_system.numbernumber
src_endpoint.ipstring
src_endpoint.location.citystring
src_endpoint.location.countrystring
src_endpoint.location.latnumber
src_endpoint.location.longnumber
statusstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber
vendor_attributes.additional_info.sampleboolean
vendor_attributes.additional_info.typestring
vendor_attributes.additional_info.valuestring
vendor_attributes.affected_resources.AWS::S3::Bucketstring
vendor_attributes.resource_rolestring
vendor_attributes.service_namestring
vendor_attributes.severitymixed
vendor_attributes.severity_idnumber