Skip to content

LegacyEventEntity

SIEM Integration API schema.

This model wraps up an Event. This contains various fields that contain information regarding the event that was generated.

Fields

amsi_threat_dataobject
Show child attributesHide child attributes
parentProcessIdstring
parentProcessPathstring
processIdstring
processNamestring
processPathstring
appCertsarray of object
Certificate info of the application associated with the threat, if available.
Show child attributesHide child attributes
signerstring
thumbprintstring
appSha256string
SHA 256 hash of the application associated with the threat, if available.
core_remedy_itemsobject
Show child attributesHide child attributes
itemsarray of object
Show child attributesHide child attributes
descriptorstring
resultstring
Must be one of: NOT_APPLICABLE, SUCCESS, NOT_FOUND, DELETED, FAILED_TO_DELETE, WHITELISTED, OTHER_ERROR, FAILED_TO_DELETE_SYSTEM_PROTECTED.
typestring
totalItemsinteger
created_atstring
The date at which the event was created.
customer_idstring
The identifier of the customer for which record is created.
detailsarray of object
Show child attributesHide child attributes
propertystring
typestring
Must be one of: CORE_EVENT_REQUEST_ID, CORE_EVENT_RESPONSE_STATUS, HMPA_EVENT_REPORT, HMPA_EVENT_TYPE, HMPA_PROCESS_VERSION, HMPA_PROCESS_PID, HMPA_PROCESS_PATH, HOME_FAMILY_ID, HOME_SCAN_LABEL, HOME_SCAN_STATE, HOME_SCAN_CLEAN, HOME_SCAN_REBOOT, HOME_COOKIES_COUNT, HOME_COOKIES_DOMAINS, HOME_REMNANT_FAMILY, HOME_REMNANT_NAME, HOME_REMNANT_PATHS, IPS_EXECUTABLE_PATH, IPS_EXECUTABLE_PID, IPS_EXECUTABLE_VERSION, IPS_EXECUTABLE_NAME, IPS_RAW_DATA, IPS_REMOTE_IP, IPS_REMOTE_PORT, IPS_LOCAL_PORT, IPS_TECH_SUPPORT_ID, AMSI_PROCESS_NAME, AMSI_PROCESS_ID, AMSI_PROCESS_PATH, AMSI_PARENT_PROCESS_ID, AMSI_PARENT_PROCESS_PATH, AMSI_THREAT_SUB_TYPE.
endpoint_idstring
The corresponding endpoint id associated with the record.
endpoint_typestring
The corresponding endpoint type associated with the record.
groupstring
The group associated with the group.
idstring
The Identifier for the event.
ips_threat_dataobject
Show child attributesHide child attributes
detectionTypeinteger
executableNamestring
executablePathstring
executablePidstring
executableVersionstring
localPortstring
rawDatastring
remoteIpstring
remotePortstring
techSupportIdstring
locationstring
The location captured for this record.
namestring
The name of the record created.
originstring
originating component of a detection.
severitystring
The severity for this alert.
Must be one of: NONE, LOW, MEDIUM, HIGH, CRITICAL.
sourcestring
The source for this record.
source_infoobject
Detailed source information for this record.
threatstring
The threat associated with the record.
typestring
The type of this record.
user_idstring
The identifier of the user for which record is created.
whenstring
The date at which the event was created.
whitelist_propertiesarray of object
Show child attributesHide child attributes
propertystring
typestring
Must be one of: SHA_256, CERTIFICATE_SIGNER, PATH, THUMBPRINT, PROCESS_NAME, MITIGATION, DETECTION_KEY.