Skip to content

This document shows the fields supported by each provider and operation.

query_alerts

FieldCrowdStrike Next-Gen SIEMPanther SIEMSplunk Enterprise SecurityType
activity_idnumber
activity_namestring
actor.app_namestring
actor.app_uidstring
actor.process.cmd_linestring
actor.process.created_timetimestamp
actor.process.created_time_dtstring
actor.process.file.hashes[].algorithmstring
actor.process.file.hashes[].algorithm_idnumber
actor.process.file.hashes[].valuestring
actor.process.file.namestring
actor.process.file.pathstring
actor.process.file.type_idnumber
actor.process.namestring
actor.process.parent_process.cmd_linestring
actor.process.parent_process.created_timetimestamp
actor.process.parent_process.created_time_dtstring
actor.process.parent_process.file.hashes[].algorithmstring
actor.process.parent_process.file.hashes[].algorithm_idnumber
actor.process.parent_process.file.hashes[].valuestring
actor.process.parent_process.file.namestring
actor.process.parent_process.file.pathstring
actor.process.parent_process.file.typestring
actor.process.parent_process.file.type_idnumber
actor.process.parent_process.namestring
actor.process.parent_process.parent_process.cmd_linestring
actor.process.parent_process.parent_process.created_timetimestamp
actor.process.parent_process.parent_process.created_time_dtstring
actor.process.parent_process.parent_process.file.hashes[].algorithmstring
actor.process.parent_process.parent_process.file.hashes[].algorithm_idnumber
actor.process.parent_process.parent_process.file.hashes[].valuestring
actor.process.parent_process.parent_process.file.namestring
actor.process.parent_process.parent_process.file.pathstring
actor.process.parent_process.parent_process.file.typestring
actor.process.parent_process.parent_process.file.type_idnumber
actor.process.parent_process.parent_process.namestring
actor.process.parent_process.parent_process.pathstring
actor.process.parent_process.parent_process.pidnumber
actor.process.parent_process.parent_process.uidstring
actor.process.parent_process.parent_process.user.namestring
actor.process.parent_process.parent_process.user.uidstring
actor.process.parent_process.pathstring
actor.process.parent_process.pidnumber
actor.process.parent_process.uidstring
actor.process.parent_process.user.namestring
actor.process.parent_process.user.uidstring
actor.process.pidnumber
actor.process.terminated_timetimestamp
actor.process.terminated_time_dtstring
actor.process.user.namestring
actor.process.user.uidstring
actor.user.full_namestring
actor.user.namestring
actor.user.uidstring
api.operationstring
api.service.namestring
attacks[].tactic.namestring
attacks[].tactic.uidstring
attacks[].technique.namestring
attacks[].technique.uidstring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
commentstring
confidencestring
confidence_idnumber
confidence_scorenumber
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.hw_info.system_manufacturerstring
device.hw_info.system_product_namestring
device.ipstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.macstring
device.modified_timetimestamp
device.modified_time_dtstring
device.network_interfaces[].hostnamestring
device.network_interfaces[].ipstring
device.network_interfaces[].macstring
device.network_interfaces[].type_idnumber
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
device.uid_altstring
end_timetimestamp
end_time_dtstring
evidences[].connection_info.directionstring
evidences[].connection_info.direction_idnumber
evidences[].connection_info.protocol_namestring
evidences[].connection_info.protocol_verstring
evidences[].connection_info.protocol_ver_idnumber
evidences[].connection_info.session.created_timetimestamp
evidences[].device.hostnamestring
evidences[].device.type_idnumber
evidences[].dst_endpoint.ipstring
evidences[].dst_endpoint.portnumber
evidences[].file.hashes[].algorithmstring
evidences[].file.hashes[].algorithm_idnumber
evidences[].file.hashes[].valuestring
evidences[].file.namestring
evidences[].file.pathstring
evidences[].file.type_idnumber
evidences[].process.cmd_linestring
evidences[].process.created_timetimestamp
evidences[].process.created_time_dtstring
evidences[].process.file.hashes[].algorithmstring
evidences[].process.file.hashes[].algorithm_idnumber
evidences[].process.file.hashes[].valuestring
evidences[].process.file.namestring
evidences[].process.file.pathstring
evidences[].process.file.type_idnumber
evidences[].process.namestring
evidences[].process.parent_process.cmd_linestring
evidences[].process.parent_process.created_timetimestamp
evidences[].process.parent_process.created_time_dtstring
evidences[].process.parent_process.file.hashes[].algorithmstring
evidences[].process.parent_process.file.hashes[].algorithm_idnumber
evidences[].process.parent_process.file.hashes[].valuestring
evidences[].process.parent_process.file.namestring
evidences[].process.parent_process.file.pathstring
evidences[].process.parent_process.file.typestring
evidences[].process.parent_process.file.type_idnumber
evidences[].process.parent_process.namestring
evidences[].process.parent_process.parent_process.cmd_linestring
evidences[].process.parent_process.parent_process.created_timetimestamp
evidences[].process.parent_process.parent_process.created_time_dtstring
evidences[].process.parent_process.parent_process.file.hashes[].algorithmstring
evidences[].process.parent_process.parent_process.file.hashes[].algorithm_idnumber
evidences[].process.parent_process.parent_process.file.hashes[].valuestring
evidences[].process.parent_process.parent_process.file.namestring
evidences[].process.parent_process.parent_process.file.pathstring
evidences[].process.parent_process.parent_process.file.typestring
evidences[].process.parent_process.parent_process.file.type_idnumber
evidences[].process.parent_process.parent_process.namestring
evidences[].process.parent_process.parent_process.pathstring
evidences[].process.parent_process.parent_process.pidnumber
evidences[].process.parent_process.parent_process.uidstring
evidences[].process.parent_process.parent_process.user.namestring
evidences[].process.parent_process.parent_process.user.uidstring
evidences[].process.parent_process.pathstring
evidences[].process.parent_process.pidnumber
evidences[].process.parent_process.uidstring
evidences[].process.parent_process.user.namestring
evidences[].process.pidnumber
evidences[].process.terminated_timetimestamp
evidences[].process.terminated_time_dtstring
evidences[].process.user.namestring
evidences[].process.user.uidstring
evidences[].src_endpoint.ipstring
evidences[].src_endpoint.portnumber
evidences[].user.namestring
evidences[].user.uidstring
finding_info.analytic.categorystring
finding_info.analytic.namestring
finding_info.analytic.typestring
finding_info.analytic.type_idnumber
finding_info.analytic.uidstring
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.descstring
finding_info.last_seen_timetimestamp
finding_info.last_seen_time_dtstring
finding_info.product_uidstring
finding_info.src_urlstring
finding_info.titlestring
finding_info.types[]string
finding_info.uidstring
messagestring
metadata.correlation_uidstring
metadata.event_codestring
metadata.labels[]string
metadata.log_providerstring
metadata.loggers[].logged_timetimestamp
metadata.loggers[].logged_time_dtstring
metadata.product.feature.namestring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
resources[].cloud_partitionstring
resources[].namestring
resources[].typestring
resources[].uidstring
risk_detailsstring
risk_levelstring
risk_level_idnumber
risk_scorenumber
severitystring
severity_idnumber
start_timetimestamp
start_time_dtstring
statusstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber
vulnerabilities[].descstring
vulnerabilities[].titlestring

query_events

FieldCrowdStrike Next-Gen SIEMGoogle Security OperationsGoogle Security Operations (Chronicle Compatibility)IBM QRadar SIEMMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEMType
action_idnumber
activity_idnumber
activity_namestring
actor.app_namestring
actor.idp.namestring
actor.process.nameunknown
actor.process.pidmixed
actor.session.uidstring
actor.user.account.namestring
actor.user.domainunknown
actor.user.email_addrstring
actor.user.full_namestring
actor.user.namemixed
actor.user.typestring
actor.user.type_idnumber
actor.user.uidmixed
actor.user.uid_altunknown
api.operationstring
auth_factors[].factor_typestring
auth_factors[].factor_type_idnumber
auth_factors[].unmapped_mechanismunknown
auth_protocolstring
auth_protocol_idnumber
category_namestring
category_uidnumber
class_namestring
class_uidnumber
cloud.providerstring
cloud.regionstring
connection_info.boundaryunknown
connection_info.boundary_idnumber
connection_info.directionstring
connection_info.direction_idnumber
connection_info.protocol_nameunknown
connection_info.protocol_numunknown
connection_info.protocol_verstring
countnumber
device.domainstring
device.hostnamestring
device.ipstring
device.last_seen_timetimestamp
device.location.descriptionstring
device.macstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.owner.namestring
device.owner.typestring
device.owner.type_idnumber
device.owner.uid_altstring
device.type_idnumber
device.uidstring
device.unmapped_noun_process_if_device.file.fullPathstring
dispositionstring
disposition_idnumber
dst_endpoint.domainmixed
dst_endpoint.hostnamestring
dst_endpoint.interface_uidstring
dst_endpoint.ipstring
dst_endpoint.location.citystring
dst_endpoint.location.countrystring
dst_endpoint.location.descriptionstring
dst_endpoint.location.latunknown
dst_endpoint.location.longunknown
dst_endpoint.location.regionstring
dst_endpoint.macstring
dst_endpoint.namestring
dst_endpoint.os.namestring
dst_endpoint.owner.namestring
dst_endpoint.owner.typestring
dst_endpoint.owner.type_idnumber
dst_endpoint.owner.uid_altstring
dst_endpoint.portnumber
dst_endpoint.svc_namestring
dst_endpoint.uidstring
durationmixed
end_timetimestamp
file.namestring
file.pathstring
file.type_idnumber
finding_info.attacks[].sub_technique.namestring
finding_info.attacks[].sub_technique.src_urlstring
finding_info.attacks[].sub_technique.uidstring
finding_info.attacks[].tactic.namestring
finding_info.attacks[].tactic.src_urlstring
finding_info.attacks[].tactic.uidstring
finding_info.attacks[].technique.namestring
finding_info.attacks[].technique.src_urlstring
finding_info.attacks[].technique.uidstring
finding_info.attacks[].versionstring
finding_info.created_timetimestamp
finding_info.descstring
finding_info.related_analytics[].categorystring
finding_info.related_analytics[].descstring
finding_info.related_analytics[].namestring
finding_info.related_analytics[].typestring
finding_info.related_analytics[].type_idnumber
finding_info.related_analytics[].uidstring
finding_info.related_analytics[].versionstring
finding_info.titlestring
finding_info.uidstring
http_request.url.portnumber
intermediaries[].hostnamestring
is_remoteboolean
job.file.namestring
job.file.type_idnumber
job.namestring
logon_process.file.pathstring
logon_process.namestring
logon_process.pidstring
logon_typestring
logon_type_idnumber
messagestring
metadata.correlation_uidstring
metadata.event_codestring
metadata.labels[]string
metadata.log_namestring
metadata.log_providerstring
metadata.log_versionstring
metadata.logged_timetimestamp
metadata.processed_timetimestamp
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
observables[].namestring
observables[].reputation.base_scorenumber
observables[].reputation.providerstring
observables[].reputation.scorestring
observables[].reputation.score_idnumber
observables[].typestring
observables[].type_idnumber
observables[].valuestring
observer.namestring
process.cmd_linestring
process.file.pathstring
process.group.namestring
process.group.uidstring
process.namestring
resource.labels[]string
resource.namestring
resource.typestring
service.namestring
session.is_remoteboolean
session.uidstring
severitystring
severity_idnumber
src_endpoint.domainmixed
src_endpoint.hostnamestring
src_endpoint.interface_uidstring
src_endpoint.ipstring
src_endpoint.location.citystring
src_endpoint.location.countrystring
src_endpoint.location.latunknown
src_endpoint.location.longunknown
src_endpoint.location.regionstring
src_endpoint.macstring
src_endpoint.namestring
src_endpoint.os.namestring
src_endpoint.os.typestring
src_endpoint.os.type_idnumber
src_endpoint.owner.typestring
src_endpoint.owner.type_idnumber
src_endpoint.owner.uid_altunknown
src_endpoint.portmixed
src_endpoint.uidstring
start_timetimestamp
statusstring
status_detailstring
status_idnumber
system.typestring
system.type_idnumber
test_extranumber
timenumber
type_namestring
type_uidnumber
user.account.namestring
user.domainstring
user.full_namestring
user.namestring
user.typestring
user.type_idnumber
user.uidstring
user.uid_altstring