Skip to content

This document shows the fields supported by each provider and operation.

query_events

FieldCrowdStrike Next-Gen SIEMGoogle Security OperationsGoogle Security Operations (Chronicle Compatibility)IBM QRadar SIEMMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEMType
action_idnumber
activity_idnumber
activity_namestring
actor.app_namestring
actor.idp.namestring
actor.process.nameunknown
actor.process.pidmixed
actor.session.uidstring
actor.user.account.namestring
actor.user.domainunknown
actor.user.email_addrstring
actor.user.full_namestring
actor.user.namemixed
actor.user.typestring
actor.user.type_idnumber
actor.user.uidmixed
actor.user.uid_altunknown
api.operationstring
auth_factors[].factor_typestring
auth_factors[].factor_type_idnumber
auth_factors[].unmapped_mechanismunknown
auth_protocolstring
auth_protocol_idnumber
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.providerstring
cloud.regionstring
connection_info.boundaryunknown
connection_info.boundary_idnumber
connection_info.directionstring
connection_info.direction_idnumber
connection_info.protocol_nameunknown
connection_info.protocol_numunknown
connection_info.protocol_verstring
countnumber
device.domainstring
device.hostnamestring
device.ipstring
device.last_seen_timetimestamp
device.location.descriptionstring
device.macstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.owner.namestring
device.owner.typestring
device.owner.type_idnumber
device.owner.uid_altstring
device.type_idnumber
device.uidstring
device.unmapped_noun_process_if_device.file.fullPathstring
dispositionstring
disposition_idnumber
dst_endpoint.domainmixed
dst_endpoint.hostnamestring
dst_endpoint.interface_uidstring
dst_endpoint.ipstring
dst_endpoint.location.citystring
dst_endpoint.location.countrystring
dst_endpoint.location.descriptionstring
dst_endpoint.location.latunknown
dst_endpoint.location.longunknown
dst_endpoint.location.regionstring
dst_endpoint.macstring
dst_endpoint.namestring
dst_endpoint.os.namestring
dst_endpoint.owner.namestring
dst_endpoint.owner.typestring
dst_endpoint.owner.type_idnumber
dst_endpoint.owner.uid_altstring
dst_endpoint.portnumber
dst_endpoint.svc_namestring
dst_endpoint.uidstring
durationmixed
end_timetimestamp
file.namestring
file.pathstring
file.type_idnumber
finding_info.attacks[].sub_technique.namestring
finding_info.attacks[].sub_technique.src_urlstring
finding_info.attacks[].sub_technique.uidstring
finding_info.attacks[].tactic.namestring
finding_info.attacks[].tactic.src_urlstring
finding_info.attacks[].tactic.uidstring
finding_info.attacks[].technique.namestring
finding_info.attacks[].technique.src_urlstring
finding_info.attacks[].technique.uidstring
finding_info.attacks[].versionstring
finding_info.created_timetimestamp
finding_info.descstring
finding_info.related_analytics[].categorystring
finding_info.related_analytics[].descstring
finding_info.related_analytics[].namestring
finding_info.related_analytics[].typestring
finding_info.related_analytics[].type_idnumber
finding_info.related_analytics[].uidstring
finding_info.related_analytics[].versionstring
finding_info.titlestring
finding_info.uidstring
http_request.url.portnumber
intermediaries[].hostnamestring
is_remoteboolean
job.file.namestring
job.file.type_idnumber
job.namestring
logon_process.file.pathstring
logon_process.namestring
logon_process.pidstring
logon_typestring
logon_type_idnumber
messagestring
metadata.correlation_uidstring
metadata.event_codestring
metadata.labels[]string
metadata.log_namestring
metadata.log_providerstring
metadata.log_versionstring
metadata.logged_timetimestamp
metadata.processed_timetimestamp
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
observables[].namestring
observables[].reputation.base_scorenumber
observables[].reputation.providerstring
observables[].reputation.scorestring
observables[].reputation.score_idnumber
observables[].typestring
observables[].type_idnumber
observables[].valuestring
observer.namestring
process.cmd_linestring
process.file.pathstring
process.group.namestring
process.group.uidstring
process.namestring
resource.labels[]string
resource.namestring
resource.typestring
service.namestring
session.is_remoteboolean
session.uidstring
severitystring
severity_idnumber
src_endpoint.domainmixed
src_endpoint.hostnamestring
src_endpoint.interface_uidstring
src_endpoint.ipstring
src_endpoint.location.citystring
src_endpoint.location.countrystring
src_endpoint.location.latunknown
src_endpoint.location.longunknown
src_endpoint.location.regionstring
src_endpoint.macstring
src_endpoint.namestring
src_endpoint.os.namestring
src_endpoint.os.typestring
src_endpoint.os.type_idnumber
src_endpoint.owner.typestring
src_endpoint.owner.type_idnumber
src_endpoint.owner.uid_altunknown
src_endpoint.portmixed
src_endpoint.uidstring
start_timetimestamp
statusstring
status_detailstring
status_idnumber
system.typestring
system.type_idnumber
test_extranumber
timenumber
type_namestring
type_uidnumber
user.account.namestring
user.domainstring
user.full_namestring
user.namestring
user.typestring
user.type_idnumber
user.uidstring
user.uid_altstring