LegacyEventEntity¶
SIEM Integration API schema.
This model wraps up an Event. This contains various fields that contain information regarding the event that was generated.
Fields¶
amsi_threat_dataobjectShow child attributesHide child attributes
parentProcessIdstringparentProcessPathstringprocessIdstringprocessNamestringprocessPathstringappCertsarray of objectCertificate info of the application associated with the threat, if available.
Show child attributesHide child attributes
signerstringthumbprintstringappSha256stringSHA 256 hash of the application associated with the threat, if available.
core_remedy_itemsobjectShow child attributesHide child attributes
itemsarray of objectShow child attributesHide child attributes
descriptorstringresultstringMust be one of:
NOT_APPLICABLE, SUCCESS, NOT_FOUND, DELETED, FAILED_TO_DELETE, WHITELISTED, OTHER_ERROR, FAILED_TO_DELETE_SYSTEM_PROTECTED.typestringtotalItemsintegercreated_atstringThe date at which the event was created.
customer_idstringThe identifier of the customer for which record is created.
detailsarray of objectShow child attributesHide child attributes
propertystringtypestringMust be one of:
CORE_EVENT_REQUEST_ID, CORE_EVENT_RESPONSE_STATUS, HMPA_EVENT_REPORT, HMPA_EVENT_TYPE, HMPA_PROCESS_VERSION, HMPA_PROCESS_PID, HMPA_PROCESS_PATH, HOME_FAMILY_ID, HOME_SCAN_LABEL, HOME_SCAN_STATE, HOME_SCAN_CLEAN, HOME_SCAN_REBOOT, HOME_COOKIES_COUNT, HOME_COOKIES_DOMAINS, HOME_REMNANT_FAMILY, HOME_REMNANT_NAME, HOME_REMNANT_PATHS, IPS_EXECUTABLE_PATH, IPS_EXECUTABLE_PID, IPS_EXECUTABLE_VERSION, IPS_EXECUTABLE_NAME, IPS_RAW_DATA, IPS_REMOTE_IP, IPS_REMOTE_PORT, IPS_LOCAL_PORT, IPS_TECH_SUPPORT_ID, AMSI_PROCESS_NAME, AMSI_PROCESS_ID, AMSI_PROCESS_PATH, AMSI_PARENT_PROCESS_ID, AMSI_PARENT_PROCESS_PATH, AMSI_THREAT_SUB_TYPE.endpoint_idstringThe corresponding endpoint id associated with the record.
endpoint_typestringThe corresponding endpoint type associated with the record.
groupstringThe group associated with the group.
idstringThe Identifier for the event.
ips_threat_dataobjectShow child attributesHide child attributes
detectionTypeintegerexecutableNamestringexecutablePathstringexecutablePidstringexecutableVersionstringlocalPortstringrawDatastringremoteIpstringremotePortstringtechSupportIdstringlocationstringThe location captured for this record.
namestringThe name of the record created.
originstringoriginating component of a detection.
severitystringThe severity for this alert.
Must be one of:
Must be one of:
NONE, LOW, MEDIUM, HIGH, CRITICAL.sourcestringThe source for this record.
source_infoobjectDetailed source information for this record.
threatstringThe threat associated with the record.
typestringThe type of this record.
user_idstringThe identifier of the user for which record is created.
whenstringThe date at which the event was created.
whitelist_propertiesarray of objectShow child attributesHide child attributes
propertystringtypestringMust be one of:
SHA_256, CERTIFICATE_SIGNER, PATH, THUMBPRINT, PROCESS_NAME, MITIGATION, DETECTION_KEY.