SIEM Supported Fields

This document shows the fields supported by each provider and operation.

query_events

FieldCrowdStrike Next-Gen SIEMGoogle Security OperationsGoogle Security Operations (Chronicle Compatibility)IBM QRadar SIEMMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEMType
ActingAppIdstring
ActingProcessIdstring
ActorUserIdstring
ActorUserIdTypestring
ActorUserTypestring
ActorUsernamestring
ActorUsernameTypestring
AdditionalFields.cloud_providerstring
AdditionalFields.cloud_regionstring
AdditionalFields.compliance_controlstring
AdditionalFields.compliance_requirementsstring
AdditionalFields.compliance_standardsstring
AdditionalFields.compliance_statusstring
AdditionalFields.finding_info_related_events[].type_namestring
AdditionalFields.finding_info_related_events[].uidstring
AdditionalFields.malware[].classification_idsunknown
AdditionalFields.malware[].namestring
AdditionalFields.malware[].pathstring
AdditionalFields.observables[].namestring
AdditionalFields.observables[].typestring
AdditionalFields.observables[].type_idnumber
AdditionalFields.observables[].valuestring
AdditionalFields.ocsf_activity_idnumber
AdditionalFields.ocsf_activity_namestring
AdditionalFields.ocsf_category_nameunknown
AdditionalFields.ocsf_category_uidnumber
AdditionalFields.ocsf_class_uidnumber
AdditionalFields.ocsf_status_idnumber
AdditionalFields.ocsf_target_user_emailstring
AdditionalFields.ocsf_timezone_offsetnumber
AdditionalFields.ocsf_type_namestring
AdditionalFields.ocsf_type_uidnumber
AdditionalFields.resources[].labels[]string
AdditionalFields.resources[].namestring
AdditionalFields.resources[].typestring
AdditionalFields.resources[].uidstring
AdditionalFields.timezone_offsetnumber
AlertDescriptionstring
AlertIdstring
AlertNamestring
AlertOriginalStatusstring
AlertStatusstring
AlertVerdictstring
Applicationstring
AttackRemediationStepsstring
AttackTacticsstring
AttackTechniquesstring
DetectionMethodstring
Dststring
Dvcstring
DvcFQDNstring
DvcHostnamestring
DvcIdstring
DvcIdTypestring
DvcIpAddrstring
DvcMacAddrstring
DvcOsstring
DvcOsVersionstring
DvcZonestring
EventCountnumber
EventEndTimestring
EventMessagestring
EventOriginalResultDetailsstring
EventOriginalSeveritystring
EventOriginalSubTypestring
EventOriginalTypestring
EventProductstring
EventProductVersionstring
EventResultstring
EventSchemastring
EventSchemaVersionstring
EventSeveritystring
EventStartTimestring
EventSubTypestring
EventTypestring
EventUidstring
EventVendorstring
Hostnamestring
IndicatorAssociationstring
IndicatorTypestring
IpAddrstring
LogonProtocolstring
Objectstring
ObjectTypestring
ProcessIdstring
Rulestring
RuleDescriptionstring
RuleNamestring
RuleNumberstring
Srcstring
SrcDescriptionstring
SrcDeviceTypestring
SrcFQDNstring
SrcHostnamestring
SrcIpAddrstring
SrcPortNumbernumber
Targetstring
TargetAppNamestring
TargetAppTypestring
TargetDescriptionstring
TargetDeviceTypestring
TargetDvcIdstring
TargetDvcIdTypestring
TargetDvcOsstring
TargetFQDNstring
TargetHostnamestring
TargetIpAddrstring
TargetOriginalUserTypestring
TargetPortNumbernumber
TargetUserIdstring
TargetUserIdTypestring
TargetUserTypestring
TargetUsernamestring
TargetUsernameTypestring
ThreatCategorystring
ThreatConfidencenumber
ThreatFirstReportedTimestring
ThreatIsActiveboolean
ThreatNamestring
ThreatOriginalCategorystring
ThreatOriginalConfidencestring
ThreatOriginalRiskLevelstring
ThreatRiskLevelnumber
TimeGeneratedstring
Userstring
UserTypestring
action_idnumber
activity_idnumber
activity_namestring
actor.app_namestring
actor.idp.namestring
actor.process.pidnumber
actor.user.email_addrstring
actor.user.full_namestring
actor.user.namestring
actor.user.typestring
actor.user.type_idnumber
actor.user.uid_altunknown
api.operationstring
auth_factors[].factor_typestring
auth_factors[].factor_type_idnumber
auth_factors[].unmapped_mechanismunknown
auth_protocolstring
auth_protocol_idnumber
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.providerstring
cloud.regionstring
countnumber
device.domainstring
device.ipstring
device.last_seen_timetimestamp
device.location.descriptionstring
device.macstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.owner.namestring
device.owner.typestring
device.owner.type_idnumber
device.owner.uid_altstring
device.type_idnumber
device.unmapped_noun_process_if_device.file.fullPathstring
dispositionstring
disposition_idnumber
dst_endpoint.domainstring
dst_endpoint.hostnamestring
dst_endpoint.ipstring
dst_endpoint.location.descriptionstring
dst_endpoint.macstring
dst_endpoint.namestring
dst_endpoint.os.namestring
dst_endpoint.owner.namestring
dst_endpoint.owner.typestring
dst_endpoint.owner.type_idnumber
dst_endpoint.owner.uid_altstring
dst_endpoint.svc_namestring
durationnumber
end_timetimestamp
http_request.url.portnumber
intermediaries[].hostnamestring
is_remoteboolean
job.file.namestring
job.file.type_idnumber
job.namestring
logon_process.file.pathstring
logon_process.namestring
logon_process.pidstring
logon_typestring
logon_type_idnumber
messagestring
metadata.correlation_uidstring
metadata.event_codemixed
metadata.labels[]string
metadata.log_namestring
metadata.log_providerstring
metadata.log_versionstring
metadata.processed_timetimestamp
metadata.product.namestring
metadata.product.vendor_namestring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
observer.namestring
process.cmd_linestring
process.file.pathstring
process.namestring
resource.labels[]string
resource.namestring
resource.typestring
risk_levelstring
risk_level_idnumber
service.namestring
session.uidstring
severitystring
severity_idnumber
src_endpoint.domainstring
src_endpoint.hostnamestring
src_endpoint.ipstring
src_endpoint.macstring
src_endpoint.namestring
src_endpoint.os.namestring
src_endpoint.os.typestring
src_endpoint.os.type_idnumber
src_endpoint.owner.typestring
src_endpoint.owner.type_idnumber
src_endpoint.owner.uid_altunknown
src_endpoint.portstring
start_timetimestamp
statusstring
status_idnumber
system.typestring
system.type_idnumber
timenumber
type_namestring
type_uidnumber
user.account.namestring
user.domainstring
user.full_namestring
user.namestring
user.typestring
user.type_idnumber
user.uid_altstring