SIEM Supported Fields

This document shows the fields supported by each provider and operation.

query_events

FieldCrowdStrike SIEMGoogle Security OperationsIBM QRadarMicrosoft SentinelSplunkSumo Logic Cloud SIEMType
action_idnumber
activity_idnumber
activity_namestring
actor.app_namestring
actor.user.email_addrstring
api.operationstring
auth_protocolstring
auth_protocol_idnumber
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.providerstring
cloud.regionstring
countnumber
device.domainstring
device.ipstring
device.last_seen_timetimestamp
device.location.descriptionstring
device.macstring
device.type_idnumber
disposition_idnumber
dst_endpoint.domainstring
dst_endpoint.hostnamestring
dst_endpoint.ipstring
dst_endpoint.location.descriptionstring
dst_endpoint.macstring
dst_endpoint.namestring
dst_endpoint.os.namestring
dst_endpoint.svc_namestring
durationnumber
end_timetimestamp
http_request.url.portnumber
job.file.namestring
job.file.type_idnumber
job.namestring
logon_process.file.pathstring
logon_process.namestring
logon_process.pidstring
logon_typestring
logon_type_idnumber
messagestring
metadata.correlation_uidstring
metadata.event_codemixed
metadata.labels[]string
metadata.log_namestring
metadata.log_providerstring
metadata.log_versionstring
metadata.processed_timetimestamp
metadata.product.namestring
metadata.product.vendor_namestring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
risk_levelstring
risk_level_idnumber
session.uidstring
severitystring
severity_idnumber
src_endpoint.domainstring
src_endpoint.ipstring
src_endpoint.macstring
src_endpoint.namestring
src_endpoint.portstring
start_timetimestamp
statusstring
status_idnumber
timenumber
type_namestring
type_uidnumber
user.account.namestring
user.domainstring
user.namestring