| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][1] | An asset, such as workstation, laptop, phone, virtual machine, etc. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][2] | User. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][3] | Group. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][4] | Resource. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][5] | An external IP address. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][6] | A file. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][7] | A domain. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][8] | A url. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][9] | A mutex. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['methods']['findRelatedEntities']['parameters']['entityTypes']['enumDescriptions'][10] | A metric. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchCuratedDetections']['parameters']['alertState']['enumDescriptions'][1] | The security result is not an alert. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchCuratedDetections']['parameters']['alertState']['enumDescriptions'][2] | The security result is an alert. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchDetections']['parameters']['alertState']['enumDescriptions'][1] | The security result is not an alert. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchDetections']['parameters']['alertState']['enumDescriptions'][2] | The security result is an alert. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][0] | An unspecified collection type. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][1] | An alert reported in customer telemetry. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][2] | A finding from the Uppercase team. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][4] | A detection found by applying a rule. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][5] | An alert generated by Chronicle machine learning models. |
|---|
| root['resources']['projects']['resources']['locations']['resources']['instances']['resources']['legacy']['methods']['legacySearchFindings']['parameters']['findingType']['enumDescriptions'][6] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['AnalystVerdict']['properties']['verdictResponse']['enumDescriptions'][1] | VerdictResponse resulted a threat as malicious. |
|---|
| root['schemas']['AnalystVerdict']['properties']['verdictResponse']['enumDescriptions'][2] | VerdictResponse resulted a threat as benign. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][1] | Minimum. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][2] | Maximum. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][3] | Count. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][4] | Sum. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][5] | Average. |
|---|
| root['schemas']['AnalyticValue']['properties']['aggregateFunction']['enumDescriptions'][6] | Standard Deviation. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][1] | Principal Device |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][2] | Target User |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][3] | Target Device |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][4] | Principal User |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][5] | Target IP |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][6] | Principal File Hash |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][7] | Principal Country |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][8] | Security Category |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][9] | Network ASN |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][10] | Client Certificate Hash |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][11] | DNS Query Type |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][12] | DNS Domain |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][13] | HTTP User Agent |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][14] | Event Type |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][15] | Product Name |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][16] | Product Event Type |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][17] | Parent Folder Path |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][18] | Target resource Name |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][19] | Principal Application. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][20] | Target Application. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][21] | Email To Address. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][22] | Email From Address. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][23] | Mail Id. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][24] | Principal IP. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][25] | Security Action. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][26] | Security Rule Id. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][27] | Target Network Organization name. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][28] | Principal Network Organization name. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][29] | Principal Process File Path. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][30] | Principal Process File SHA256 Hash. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][31] | Security Result rule name. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][32] | Target Resource label key. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][33] | Vendor name. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][34] | Target Resource type. |
|---|
| root['schemas']['AnalyticValue']['properties']['dimensions']['items']['enumDescriptions'][35] | Target Location name. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][1] | Activity related to a process which does not match any other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][2] | Process launch. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][3] | Process injecting into another process. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][4] | Process privilege escalation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][5] | Process termination. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][6] | Process being opened. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][7] | Process loading a module. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][8] | Registry event which does not match any of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][9] | Registry creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][10] | Registry modification. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][11] | Registry deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][12] | Settings-related event which does not match any of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][13] | Setting creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][14] | Setting modification. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][15] | Setting deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][16] | Any mutex event other than creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][17] | Mutex creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][18] | File event which does not match any of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][19] | File created. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][20] | File deleted. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][21] | File modified. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][22] | File read. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][23] | File copied. Used for file copies, for example, to a thumb drive. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][24] | File opened. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][25] | File moved or renamed. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][26] | File synced (for example, Google Drive, Dropbox, backup). |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][27] | User activity which does not match any of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][28] | User login. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][29] | User logout. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][30] | User creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][31] | User password change event. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][32] | Change in user permissions. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][33] | Deprecated. Used to update user info for an LDAP dump. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][34] | User physically badging into a location. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][35] | User deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][36] | User creating a virtual resource. This is equivalent to RESOURCE_CREATION. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][37] | User updating content of a virtual resource. This is equivalent to RESOURCE_WRITTEN. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][38] | User updating permissions of a virtual resource. This is equivalent to RESOURCE_PERMISSIONS_CHANGE. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][39] | User initiating communication through a medium (for example, video). |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][40] | User accessing a virtual resource. This is equivalent to RESOURCE_READ. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][41] | User deleting a virtual resource. This is equivalent to RESOURCE_DELETION. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][42] | A group activity that does not fall into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][43] | A group creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][44] | A group deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][45] | A group modification. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][46] | Email messages |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][47] | An email transaction. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][48] | Deprecated: use NETWORK_HTTP instead. An email URL click event. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][49] | A network event that does not fit into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][50] | Aggregated flow stats like netflow. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][51] | Network connection details like from a FW. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][52] | FTP telemetry. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][53] | DHCP payload. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][54] | DNS payload. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][55] | HTTP telemetry. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][56] | SMTP telemetry. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][57] | A status message that does not fit into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][58] | Heartbeat indicating product is alive. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][59] | An agent startup. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][60] | An agent shutdown. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][61] | A software or fingerprint update. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][62] | Scan item that does not fit into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][63] | A file scan. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][64] | Scan process behaviors. Please use SCAN_PROCESS instead. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][65] | Scan process. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][66] | Scan results from scanning an entire host device for threats/sensitive documents. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][67] | Vulnerability scan logs about host vulnerabilities (e.g., out of date software) and network vulnerabilities (e.g., unprotected service detected via a network scan). |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][68] | Vulnerability scan logs about network vulnerabilities. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][69] | Scan network for suspicious activity |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][70] | Scheduled task event that does not fall into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][71] | Scheduled task creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][72] | Scheduled task deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][73] | Scheduled task being enabled. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][74] | Scheduled task being disabled. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][75] | Scheduled task being modified. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][76] | A system audit log event that is not a wipe. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][77] | A system audit log wipe. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][78] | Service event that does not fit into one of the other event types. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][79] | A service creation. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][80] | A service deletion. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][81] | A service start. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][82] | A service stop. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][83] | A service modification. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][84] | Operating system events that are not described by any of the other event types. Might include uncategorized Microsoft Windows event logs. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][85] | The resource was created/provisioned. This is equivalent to USER_RESOURCE_CREATION. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][86] | The resource was deleted/deprovisioned. This is equivalent to USER_RESOURCE_DELETION. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][87] | The resource had it's permissions or ACLs updated. This is equivalent to USER_RESOURCE_UPDATE_PERMISSIONS. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][88] | The resource was read. This is equivalent to USER_RESOURCE_ACCESS. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][89] | The resource was written to. This is equivalent to USER_RESOURCE_UPDATE_CONTENT. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][90] | Firmware update. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][91] | Configuration update. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][92] | A program or application uploaded to a device. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][93] | A program or application downloaded to a device. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][94] | Analyst update about the Verdict (such as true positive, false positive, or disregard) of a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][95] | Analyst update about the Reputation (such as useful or not useful) of a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][96] | Analyst update about the Severity score (0-100) of a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][97] | Analyst update about the finding status. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][98] | Analyst addition of a comment for a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][99] | Analyst update about the priority (such as low, medium, or high) for a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][100] | Analyst update about the root cause for a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][101] | Analyst update about the reason (such as malicious or not malicious) for a finding. |
|---|
| root['schemas']['AnalyticValue']['properties']['eventType']['enumDescriptions'][102] | Analyst update about the risk score (0-100) of a finding. |
|---|
| root['schemas']['Asset']['properties']['deploymentStatus']['enumDescriptions'][1] | Asset is active, functional and deployed. |
|---|
| root['schemas']['Asset']['properties']['deploymentStatus']['enumDescriptions'][2] | Asset is pending decommission and no longer deployed. |
|---|
| root['schemas']['Asset']['properties']['deploymentStatus']['enumDescriptions'][3] | Asset is decommissioned. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][1] | A workstation or desktop. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][2] | A laptop computer. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][3] | An IOT asset. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][4] | A network attached storage device. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][5] | A printer. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][6] | A scanner. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][7] | A server. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][8] | A tape library device. |
|---|
| root['schemas']['Asset']['properties']['type']['enumDescriptions'][9] | A mobile device such as a mobile phone or PDA. |
|---|
| root['schemas']['Association']['properties']['type']['enumDescriptions'][1] | Association type Threat actor. |
|---|
| root['schemas']['Association']['properties']['type']['enumDescriptions'][2] | Association type Malware. |
|---|
| root['schemas']['AssociationIdentity']['properties']['associationType']['enumDescriptions'][1] | Association type Threat actor. |
|---|
| root['schemas']['AssociationIdentity']['properties']['associationType']['enumDescriptions'][2] | Association type Malware. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][1] | Username + password authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][2] | OTP authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][3] | Hardware key authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][4] | Local authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][5] | Remote authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][6] | RDP, Terminal Services, or VNC. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][7] | Some other mechanism that is not defined here. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][8] | Badge reader authentication |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][9] | Network authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][10] | Batch authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][11] | Service authentication |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][12] | Direct human-interactive unlock authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][13] | Network clear text authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][14] | Authentication with new credentials. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][15] | Interactive authentication. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][16] | Interactive authentication using cached credentials. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][17] | Cached Remote Interactive authentication using cached credentials. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][19] | Biometric device such as a fingerprint reader. |
|---|
| root['schemas']['Authentication']['properties']['mechanism']['items']['enumDescriptions'][20] | Wearable such as an Apple Watch. |
|---|
| root['schemas']['Authentication']['properties']['type']['enumDescriptions'][1] | A machine authentication. |
|---|
| root['schemas']['Authentication']['properties']['type']['enumDescriptions'][2] | An SSO authentication. |
|---|
| root['schemas']['Authentication']['properties']['type']['enumDescriptions'][3] | A VPN authentication. |
|---|
| root['schemas']['Authentication']['properties']['type']['enumDescriptions'][4] | A Physical authentication (e.g. "Badge reader"). |
|---|
| root['schemas']['Authentication']['properties']['type']['enumDescriptions'][5] | A TACACS family protocol for networked systems authentication (e.g. TACACS, TACACS+). |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][20] | FILE_TYPE_DESKTOP_ENTRY |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][82] | FILE_TYPE_SLK |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][111] | FILE_TYPE_MSIX |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][143] | FILE_TYPE_RDP |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][160] | FILE_TYPE_HTA |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enum'][161] | FILE_TYPE_INTERNET_SHORTCUT |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][1] | File type is PE_EXE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][2] | Although DLLs are actually portable executables, this value enables the file type to be identified separately. File type is PE_DLL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][3] | File type is MSI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][4] | File type is NE_EXE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][5] | File type is NE_DLL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][6] | File type is DOS_EXE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][7] | File type is DOS_COM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][8] | File type is COFF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][9] | File type is ELF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][10] | File type is LINUX_KERNEL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][11] | File type is RPM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][12] | File type is LINUX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][13] | File type is MACH_O. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][14] | File type is JAVA_BYTECODE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][15] | File type is DMG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][16] | File type is DEB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][17] | File type is PKG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][18] | File type is PYC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][19] | File type is LNK. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][20] | File type is DESKTOP_ENTRY. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][21] | File type is JPEG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][22] | File type is TIFF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][23] | File type is GIF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][24] | File type is PNG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][25] | File type is BMP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][26] | File type is GIMP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][27] | File type is Adobe InDesign. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][28] | File type is PSD. Adobe Photoshop. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][29] | File type is TARGA. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][30] | File type is XWD. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][31] | File type is DIB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][32] | File type is JNG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][33] | File type is ICO. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][34] | File type is FPX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][35] | File type is EPS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][36] | File type is SVG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][37] | File type is EMF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][38] | File type is WEBP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][39] | File type is DWG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][40] | File type is DXF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][41] | File type is 3DS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][42] | File type is OGG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][43] | File type is FLC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][44] | File type is FLI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][45] | File type is MP3. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][46] | File type is FLAC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][47] | File type is WAV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][48] | File type is MIDI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][49] | File type is AVI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][50] | File type is MPEG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][51] | File type is QUICKTIME. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][52] | File type is ASF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][53] | File type is DIVX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][54] | File type is FLV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][55] | File type is WMA. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][56] | File type is WMV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][57] | File type is RM. RealMedia type. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][58] | File type is MOV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][59] | File type is MP4. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][60] | File type is T3GP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][61] | File type is WEBM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][62] | File type is MKV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][63] | File type is PDF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][64] | File type is PS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][65] | File type is DOC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][66] | File type is DOCX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][67] | File type is PPT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][68] | File type is PPTX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][69] | File type is XLS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][70] | File type is XLSX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][71] | File type is RTF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][72] | File type is PPSX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][73] | File type is ODP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][74] | File type is ODS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][75] | File type is ODT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][76] | File type is HWP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][77] | File type is GUL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][78] | File type is ODF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][79] | File type is ODG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][80] | File type is ONE_NOTE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][81] | File type is OOXML. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][82] | File type is SLK. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][83] | File type is EBOOK. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][84] | File type is LATEX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][85] | File type is TTF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][86] | File type is EOT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][87] | File type is WOFF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][88] | File type is CHM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][89] | File type is ZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][90] | File type is GZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][91] | File type is BZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][92] | File type is RZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][93] | File type is DZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][94] | File type is SEVENZIP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][95] | File type is CAB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][96] | File type is JAR. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][97] | File type is RAR. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][98] | File type is MSCOMPRESS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][99] | File type is ACE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][100] | File type is ARC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][101] | File type is ARJ. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][102] | File type is ASD. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][103] | File type is BLACKHOLE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][104] | File type is KGB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][105] | File type is ZLIB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][106] | File type is TAR. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][107] | File type is ZST. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][108] | File type is LZFSE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][109] | File type is PYTHON_WHL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][110] | File type is PYTHON_PKG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][111] | File type is MSIX, new Windows app package format. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][112] | File type is TEXT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][113] | File type is SCRIPT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][114] | File type is PHP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][115] | File type is PYTHON. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][116] | File type is PERL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][117] | File type is RUBY. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][118] | File type is C. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][119] | File type is CPP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][120] | File type is JAVA. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][121] | File type is SHELLSCRIPT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][122] | File type is PASCAL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][123] | File type is AWK. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][124] | File type is DYALOG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][125] | File type is FORTRAN. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][126] | File type is JAVASCRIPT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][127] | File type is POWERSHELL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][128] | File type is VBA. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][129] | File type is M4. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][130] | File type is OBJETIVEC. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][131] | File type is JMOD. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][132] | File type is MAKEFILE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][133] | File type is INI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][134] | File type is CLJ. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][135] | File type is PDB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][136] | File type is SQL. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][137] | File type is NEKO. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][138] | File type is WER. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][139] | File type is GOLANG. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][140] | File type is M3U. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][141] | File type is BAT, Windows .bat/.cmd (old files are tagged as SHELLSCRIPT). |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][142] | File type is MSC, Microsoft Management Console (MMC). |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][143] | File type is RDP, Microsoft Remote Desktop Protocol (RDP) file. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][144] | File type is SYMBIAN. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][145] | File type is PALMOS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][146] | File type is WINCE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][147] | File type is ANDROID. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][148] | File type is IPHONE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][149] | File type is HTML. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][150] | File type is XML. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][151] | File type is SWF. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][152] | File type is FLA. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][153] | File type is COOKIE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][154] | File type is TORRENT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][155] | File type is EMAIL_TYPE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][156] | File type is OUTLOOK. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][157] | File type is SGML. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][158] | File type is JSON. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][159] | File type is CSV. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][160] | File type is HTA (HTML Application). |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][161] | File type is MSHTML .url. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][162] | File type is CAP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][163] | File type is ISOIMAGE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][164] | File type is SQUASHFS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][165] | File type is VHD. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][166] | File type is APPLE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][167] | File type is MACINTOSH. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][168] | File type is APPLESINGLE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][169] | File type is APPLEDOUBLE. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][170] | File type is MACINTOSH_HFS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][171] | File type is APPLE_PLIST. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][172] | File type is MACINTOSH_LIB. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][173] | File type is APPLESCRIPT. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][174] | File type is APPLESCRIPT_COMPILED . |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][175] | File type is CRX. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][176] | File type is XPI. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][177] | File type is ROM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][178] | File type is IPS. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][179] | File type is PEM. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][180] | File type is PGP. |
|---|
| root['schemas']['BackstoryFile']['properties']['fileType']['enumDescriptions'][181] | File type is CRT. |
|---|
| root['schemas']['ChartDatasource']['properties']['dataSources']['items']['enum'][8] | RULES |
|---|
| root['schemas']['ChartDatasource']['properties']['dataSources']['items']['enumDescriptions'][8] | RULES is used for rules datasource. |
|---|
| root['schemas']['Cloud']['properties']['environment']['enumDescriptions'][1] | Google Cloud Platform. |
|---|
| root['schemas']['Cloud']['properties']['environment']['enumDescriptions'][2] | Amazon Web Services. |
|---|
| root['schemas']['Cloud']['properties']['environment']['enumDescriptions'][3] | Microsoft Azure. |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][1] | Ingested Raw telemetry |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][2] | Chronicle Rules engine |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][3] | Uppercase |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][4] | DSML - Machine Intelligence |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][5] | A normalized telemetry event from Google Security Command Center. |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][6] | Unspecified Namespace |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][7] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['Collection']['properties']['idNamespace']['enumDescriptions'][8] | VirusTotal. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][0] | An unspecified collection type. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][1] | An alert reported in customer telemetry. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][2] | A finding from the Uppercase team. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][4] | A detection found by applying a rule. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][5] | An alert generated by Chronicle machine learning models. |
|---|
| root['schemas']['Collection']['properties']['type']['enumDescriptions'][6] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['ColumnMetadata']['properties']['dataSource']['enum'][8] | RULES |
|---|
| root['schemas']['ColumnMetadata']['properties']['dataSource']['enumDescriptions'][8] | RULES is used for rules datasource. |
|---|
| root['schemas']['DashboardFilter']['properties']['dataSource']['enum'][8] | RULES |
|---|
| root['schemas']['DashboardFilter']['properties']['dataSource']['enumDescriptions'][8] | RULES is used for rules datasource. |
|---|
| root['schemas']['Dhcp']['properties']['opcode']['enumDescriptions'][1] | Request. |
|---|
| root['schemas']['Dhcp']['properties']['opcode']['enumDescriptions'][2] | Reply. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][1] | DHCPDISCOVER. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][2] | DHCPOFFER. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][3] | DHCPREQUEST. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][4] | DHCPDECLINE. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][5] | DHCPACK. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][6] | DHCPNAK. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][7] | DHCPRELEASE. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][8] | DHCPINFORM. |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][9] | Microsoft Windows DHCP "lease deleted". |
|---|
| root['schemas']['Dhcp']['properties']['type']['enumDescriptions'][10] | Microsoft Windows DHCP "lease expired". |
|---|
| root['schemas']['EdrEvent']['properties']['dataSource']['enum'][23] | TRELLIX |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][1] | Activity related to a process which does not match any other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][2] | Process launch. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][3] | Process injecting into another process. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][4] | Process privilege escalation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][5] | Process termination. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][6] | Process being opened. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][7] | Process loading a module. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][8] | Registry event which does not match any of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][9] | Registry creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][10] | Registry modification. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][11] | Registry deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][12] | Settings-related event which does not match any of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][13] | Setting creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][14] | Setting modification. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][15] | Setting deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][16] | Any mutex event other than creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][17] | Mutex creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][18] | File event which does not match any of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][19] | File created. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][20] | File deleted. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][21] | File modified. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][22] | File read. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][23] | File copied. Used for file copies, for example, to a thumb drive. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][24] | File opened. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][25] | File moved or renamed. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][26] | File synced (for example, Google Drive, Dropbox, backup). |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][27] | User activity which does not match any of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][28] | User login. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][29] | User logout. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][30] | User creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][31] | User password change event. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][32] | Change in user permissions. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][33] | Deprecated. Used to update user info for an LDAP dump. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][34] | User physically badging into a location. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][35] | User deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][36] | User creating a virtual resource. This is equivalent to RESOURCE_CREATION. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][37] | User updating content of a virtual resource. This is equivalent to RESOURCE_WRITTEN. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][38] | User updating permissions of a virtual resource. This is equivalent to RESOURCE_PERMISSIONS_CHANGE. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][39] | User initiating communication through a medium (for example, video). |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][40] | User accessing a virtual resource. This is equivalent to RESOURCE_READ. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][41] | User deleting a virtual resource. This is equivalent to RESOURCE_DELETION. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][42] | A group activity that does not fall into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][43] | A group creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][44] | A group deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][45] | A group modification. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][46] | Email messages |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][47] | An email transaction. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][48] | Deprecated: use NETWORK_HTTP instead. An email URL click event. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][49] | A network event that does not fit into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][50] | Aggregated flow stats like netflow. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][51] | Network connection details like from a FW. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][52] | FTP telemetry. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][53] | DHCP payload. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][54] | DNS payload. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][55] | HTTP telemetry. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][56] | SMTP telemetry. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][57] | A status message that does not fit into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][58] | Heartbeat indicating product is alive. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][59] | An agent startup. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][60] | An agent shutdown. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][61] | A software or fingerprint update. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][62] | Scan item that does not fit into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][63] | A file scan. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][64] | Scan process behaviors. Please use SCAN_PROCESS instead. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][65] | Scan process. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][66] | Scan results from scanning an entire host device for threats/sensitive documents. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][67] | Vulnerability scan logs about host vulnerabilities (e.g., out of date software) and network vulnerabilities (e.g., unprotected service detected via a network scan). |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][68] | Vulnerability scan logs about network vulnerabilities. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][69] | Scan network for suspicious activity |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][70] | Scheduled task event that does not fall into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][71] | Scheduled task creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][72] | Scheduled task deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][73] | Scheduled task being enabled. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][74] | Scheduled task being disabled. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][75] | Scheduled task being modified. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][76] | A system audit log event that is not a wipe. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][77] | A system audit log wipe. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][78] | Service event that does not fit into one of the other event types. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][79] | A service creation. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][80] | A service deletion. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][81] | A service start. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][82] | A service stop. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][83] | A service modification. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][84] | Operating system events that are not described by any of the other event types. Might include uncategorized Microsoft Windows event logs. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][85] | The resource was created/provisioned. This is equivalent to USER_RESOURCE_CREATION. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][86] | The resource was deleted/deprovisioned. This is equivalent to USER_RESOURCE_DELETION. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][87] | The resource had it's permissions or ACLs updated. This is equivalent to USER_RESOURCE_UPDATE_PERMISSIONS. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][88] | The resource was read. This is equivalent to USER_RESOURCE_ACCESS. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][89] | The resource was written to. This is equivalent to USER_RESOURCE_UPDATE_CONTENT. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][90] | Firmware update. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][91] | Configuration update. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][92] | A program or application uploaded to a device. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][93] | A program or application downloaded to a device. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][94] | Analyst update about the Verdict (such as true positive, false positive, or disregard) of a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][95] | Analyst update about the Reputation (such as useful or not useful) of a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][96] | Analyst update about the Severity score (0-100) of a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][97] | Analyst update about the finding status. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][98] | Analyst addition of a comment for a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][99] | Analyst update about the priority (such as low, medium, or high) for a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][100] | Analyst update about the root cause for a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][101] | Analyst update about the reason (such as malicious or not malicious) for a finding. |
|---|
| root['schemas']['EnrichmentDisablementTarget']['properties']['eventType']['enumDescriptions'][102] | Analyst update about the risk score (0-100) of a finding. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][1] | An asset, such as workstation, laptop, phone, virtual machine, etc. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][2] | User. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][3] | Group. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][4] | Resource. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][5] | An external IP address. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][6] | A file. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][7] | A domain. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][8] | A url. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][9] | A mutex. |
|---|
| root['schemas']['EntityGroupMetadata']['properties']['entityType']['enumDescriptions'][10] | A metric. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][1] | An asset, such as workstation, laptop, phone, virtual machine, etc. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][2] | User. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][3] | Group. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][4] | Resource. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][5] | An external IP address. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][6] | A file. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][7] | A domain. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][8] | A url. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][9] | A mutex. |
|---|
| root['schemas']['EntityMetadata']['properties']['entityType']['enumDescriptions'][10] | A metric. |
|---|
| root['schemas']['EntityMetadata']['properties']['sourceType']['enumDescriptions'][1] | Entities ingested from customers (e.g. AD_CONTEXT, DLP_CONTEXT) |
|---|
| root['schemas']['EntityMetadata']['properties']['sourceType']['enumDescriptions'][2] | Entities derived from customer data such as prevalence, artifact first/last seen, or asset/user first seen stats. |
|---|
| root['schemas']['EntityMetadata']['properties']['sourceType']['enumDescriptions'][3] | Global contextual entities such as WHOIS or Safe Browsing. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][1] | Activity related to a process which does not match any other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][2] | Process launch. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][3] | Process injecting into another process. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][4] | Process privilege escalation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][5] | Process termination. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][6] | Process being opened. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][7] | Process loading a module. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][8] | Registry event which does not match any of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][9] | Registry creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][10] | Registry modification. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][11] | Registry deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][12] | Settings-related event which does not match any of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][13] | Setting creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][14] | Setting modification. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][15] | Setting deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][16] | Any mutex event other than creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][17] | Mutex creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][18] | File event which does not match any of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][19] | File created. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][20] | File deleted. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][21] | File modified. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][22] | File read. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][23] | File copied. Used for file copies, for example, to a thumb drive. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][24] | File opened. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][25] | File moved or renamed. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][26] | File synced (for example, Google Drive, Dropbox, backup). |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][27] | User activity which does not match any of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][28] | User login. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][29] | User logout. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][30] | User creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][31] | User password change event. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][32] | Change in user permissions. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][33] | Deprecated. Used to update user info for an LDAP dump. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][34] | User physically badging into a location. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][35] | User deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][36] | User creating a virtual resource. This is equivalent to RESOURCE_CREATION. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][37] | User updating content of a virtual resource. This is equivalent to RESOURCE_WRITTEN. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][38] | User updating permissions of a virtual resource. This is equivalent to RESOURCE_PERMISSIONS_CHANGE. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][39] | User initiating communication through a medium (for example, video). |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][40] | User accessing a virtual resource. This is equivalent to RESOURCE_READ. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][41] | User deleting a virtual resource. This is equivalent to RESOURCE_DELETION. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][42] | A group activity that does not fall into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][43] | A group creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][44] | A group deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][45] | A group modification. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][46] | Email messages |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][47] | An email transaction. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][48] | Deprecated: use NETWORK_HTTP instead. An email URL click event. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][49] | A network event that does not fit into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][50] | Aggregated flow stats like netflow. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][51] | Network connection details like from a FW. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][52] | FTP telemetry. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][53] | DHCP payload. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][54] | DNS payload. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][55] | HTTP telemetry. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][56] | SMTP telemetry. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][57] | A status message that does not fit into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][58] | Heartbeat indicating product is alive. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][59] | An agent startup. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][60] | An agent shutdown. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][61] | A software or fingerprint update. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][62] | Scan item that does not fit into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][63] | A file scan. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][64] | Scan process behaviors. Please use SCAN_PROCESS instead. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][65] | Scan process. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][66] | Scan results from scanning an entire host device for threats/sensitive documents. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][67] | Vulnerability scan logs about host vulnerabilities (e.g., out of date software) and network vulnerabilities (e.g., unprotected service detected via a network scan). |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][68] | Vulnerability scan logs about network vulnerabilities. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][69] | Scan network for suspicious activity |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][70] | Scheduled task event that does not fall into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][71] | Scheduled task creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][72] | Scheduled task deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][73] | Scheduled task being enabled. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][74] | Scheduled task being disabled. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][75] | Scheduled task being modified. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][76] | A system audit log event that is not a wipe. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][77] | A system audit log wipe. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][78] | Service event that does not fit into one of the other event types. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][79] | A service creation. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][80] | A service deletion. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][81] | A service start. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][82] | A service stop. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][83] | A service modification. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][84] | Operating system events that are not described by any of the other event types. Might include uncategorized Microsoft Windows event logs. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][85] | The resource was created/provisioned. This is equivalent to USER_RESOURCE_CREATION. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][86] | The resource was deleted/deprovisioned. This is equivalent to USER_RESOURCE_DELETION. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][87] | The resource had it's permissions or ACLs updated. This is equivalent to USER_RESOURCE_UPDATE_PERMISSIONS. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][88] | The resource was read. This is equivalent to USER_RESOURCE_ACCESS. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][89] | The resource was written to. This is equivalent to USER_RESOURCE_UPDATE_CONTENT. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][90] | Firmware update. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][91] | Configuration update. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][92] | A program or application uploaded to a device. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][93] | A program or application downloaded to a device. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][94] | Analyst update about the Verdict (such as true positive, false positive, or disregard) of a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][95] | Analyst update about the Reputation (such as useful or not useful) of a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][96] | Analyst update about the Severity score (0-100) of a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][97] | Analyst update about the finding status. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][98] | Analyst addition of a comment for a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][99] | Analyst update about the priority (such as low, medium, or high) for a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][100] | Analyst update about the root cause for a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][101] | Analyst update about the reason (such as malicious or not malicious) for a finding. |
|---|
| root['schemas']['EventTypesSuggestion']['properties']['eventType']['enumDescriptions'][102] | Analyst update about the risk score (0-100) of a finding. |
|---|
| root['schemas']['ExecuteDashboardQueryResponse']['properties']['dataSources']['items']['enum'][8] | RULES |
|---|
| root['schemas']['ExecuteDashboardQueryResponse']['properties']['dataSources']['items']['enumDescriptions'][8] | RULES is used for rules datasource. |
|---|
| root['schemas']['FeedDetails']['properties']['feedSourceType']['enum'][21] | AZURE_BLOBSTORE_V2 |
|---|
| root['schemas']['FeedDetails']['properties']['feedSourceType']['enumDescriptions'][21] | Azure Blobstore Feed backed by Omniflow STS. |
|---|
| root['schemas']['FeedSourceTypeSchema']['properties']['feedSourceType']['enum'][21] | AZURE_BLOBSTORE_V2 |
|---|
| root['schemas']['FeedSourceTypeSchema']['properties']['feedSourceType']['enumDescriptions'][21] | Azure Blobstore Feed backed by Omniflow STS. |
|---|
| root['schemas']['Feedback']['properties']['priority']['enumDescriptions'][1] | Informational priority. |
|---|
| root['schemas']['Feedback']['properties']['priority']['enumDescriptions'][2] | Low priority. |
|---|
| root['schemas']['Feedback']['properties']['priority']['enumDescriptions'][3] | Medium priority. |
|---|
| root['schemas']['Feedback']['properties']['priority']['enumDescriptions'][4] | High priority. |
|---|
| root['schemas']['Feedback']['properties']['priority']['enumDescriptions'][5] | Critical priority. |
|---|
| root['schemas']['Feedback']['properties']['reason']['enumDescriptions'][1] | Case or Alert not malicious. |
|---|
| root['schemas']['Feedback']['properties']['reason']['enumDescriptions'][2] | Case or Alert is malicious. |
|---|
| root['schemas']['Feedback']['properties']['reason']['enumDescriptions'][3] | Case or Alert is under maintenance. |
|---|
| root['schemas']['Feedback']['properties']['reputation']['enumDescriptions'][1] | A categorization of the finding as useful. |
|---|
| root['schemas']['Feedback']['properties']['reputation']['enumDescriptions'][2] | A categorization of the finding as not useful. |
|---|
| root['schemas']['Feedback']['properties']['status']['enumDescriptions'][1] | New finding. |
|---|
| root['schemas']['Feedback']['properties']['status']['enumDescriptions'][2] | When a finding has feedback. |
|---|
| root['schemas']['Feedback']['properties']['status']['enumDescriptions'][3] | When an analyst closes an finding. |
|---|
| root['schemas']['Feedback']['properties']['status']['enumDescriptions'][4] | Open. Used to indicate that a Case / Alert is open. |
|---|
| root['schemas']['Feedback']['properties']['verdict']['enumDescriptions'][1] | A categorization of the finding as a "true positive". |
|---|
| root['schemas']['Feedback']['properties']['verdict']['enumDescriptions'][2] | A categorization of the finding as a "false positive". |
|---|
| root['schemas']['FindingVariable']['properties']['type']['enumDescriptions'][1] | A variable coming from the match conditions. |
|---|
| root['schemas']['FindingVariable']['properties']['type']['enumDescriptions'][2] | A variable representing significant data that was found in the detection logic. |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][1] | Ingested Raw telemetry |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][2] | Chronicle Rules engine |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][3] | Uppercase |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][4] | DSML - Machine Intelligence |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][5] | A normalized telemetry event from Google Security Command Center. |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][6] | Unspecified Namespace |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][7] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['Id']['properties']['namespace']['enumDescriptions'][8] | VirusTotal. |
|---|
| root['schemas']['Investigation']['properties']['priority']['enumDescriptions'][1] | Informational priority. |
|---|
| root['schemas']['Investigation']['properties']['priority']['enumDescriptions'][2] | Low priority. |
|---|
| root['schemas']['Investigation']['properties']['priority']['enumDescriptions'][3] | Medium priority. |
|---|
| root['schemas']['Investigation']['properties']['priority']['enumDescriptions'][4] | High priority. |
|---|
| root['schemas']['Investigation']['properties']['priority']['enumDescriptions'][5] | Critical priority. |
|---|
| root['schemas']['Investigation']['properties']['reason']['enumDescriptions'][1] | Case or Alert not malicious. |
|---|
| root['schemas']['Investigation']['properties']['reason']['enumDescriptions'][2] | Case or Alert is malicious. |
|---|
| root['schemas']['Investigation']['properties']['reason']['enumDescriptions'][3] | Case or Alert is under maintenance. |
|---|
| root['schemas']['Investigation']['properties']['reputation']['enumDescriptions'][1] | A categorization of the finding as useful. |
|---|
| root['schemas']['Investigation']['properties']['reputation']['enumDescriptions'][2] | A categorization of the finding as not useful. |
|---|
| root['schemas']['Investigation']['properties']['status']['enumDescriptions'][1] | New finding. |
|---|
| root['schemas']['Investigation']['properties']['status']['enumDescriptions'][2] | When a finding has feedback. |
|---|
| root['schemas']['Investigation']['properties']['status']['enumDescriptions'][3] | When an analyst closes an finding. |
|---|
| root['schemas']['Investigation']['properties']['status']['enumDescriptions'][4] | Open. Used to indicate that a Case / Alert is open. |
|---|
| root['schemas']['Investigation']['properties']['verdict']['enumDescriptions'][1] | A categorization of the finding as a "true positive". |
|---|
| root['schemas']['Investigation']['properties']['verdict']['enumDescriptions'][2] | A categorization of the finding as a "false positive". |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][90] | TRENDMICRO_CLOUD_EMAIL_GATEWAY_PROTECTION |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][91] | FRONT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][92] | DBDEV_ZOOM_ACTIVITY_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][94] | VUHL_SO_IDH |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][95] | AWS_LAMBDA_FUNCTION |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][96] | MASMOVIL_GENERIC_CSV_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][97] | MASMOVIL_GENERIC_JSON_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][98] | MASMOVIL_GENERIC_SYSLOG_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][99] | MASMOVIL_GENERIC_KV_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][100] | MASMOVIL_GENERIC_XML_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][101] | MASMOVIL_GENERIC_SYSLOGKV_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][102] | MASMOVIL_GENERIC_SYSLOGJSON_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][103] | MASMOVIL_GENERIC_SYSLOGXML_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][104] | MASMOVIL_GENERIC_LEEF_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][105] | MASMOVIL_GENERIC_CEF_1 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][221] | TEHTRIS_EDR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][222] | PLUMFINTECH_PLUM_BACKOFFICE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][223] | GCLDW_CLODWAVE_HIDS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][243] | CYNERIO_NDR_H |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][282] | WIREGUARD_VPN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][290] | CLAVISTER_FIREWALL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][427] | PROOFPOINT_IDENTITY_THREAT_PLATFORM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][467] | VICARIUS_VRX_EVENTS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][603] | FORTINET_ADC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][622] | HUAWEI_WIRELESS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][627] | AZURE_VNET_FLOW |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][629] | CISCO_NETFLOW |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][641] | BELDEN_SWITCH |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][666] | HP_ROUTER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][681] | VELOCLOUD_SDWAN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][708] | TRENDMICRO_VISION_ONE_ACTIVITY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][709] | TRENDMICRO_VISION_ONE_DETECTIONS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][710] | TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][745] | TRELLIX_HX_AUDIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][807] | RAVEN_DB |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][827] | AZURE_RISKY_USERS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][828] | AZURE_RISK_EVENTS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][829] | AZURE_SERVICE_PRINCIPAL_LOGINS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][859] | D_OPENPATH_CONTEXT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][873] | CIP_FASTWEB_IOC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][947] | SOLIDSERVER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][990] | HLX_FASTWEB_LOG |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][991] | CMB_FASTWEB_LOG |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1013] | WFA_FASTWEB_LOG |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1020] | PINGONE_AIC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1021] | PINGONE_PROTECT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1129] | FRCPT_FORCEPOINT_MAILCONTROL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1130] | FOXPASS_AUDIT_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1131] | DRAYTEK_ROUTER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1132] | CHROMEOS_XDR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1133] | VECTRA_XDR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1134] | METABASE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1135] | HUAWEI_FUSIONSPHERE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1136] | HUAWEI_FIREWALL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1281] | MY_SAILPOINT_LIFECYCLE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1366] | ONEIDENTITY_SAFEGUARD |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1399] | CLICKHOUSE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1422] | JOBLOGIC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1461] | ZOHO_ASSIST |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1483] | OPENTEXT_CORDY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1526] | CLOUDFLARE_NETWORK_ANALYTICS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1556] | CROWDSTRIKE_DLP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1625] | JAMF_TELEMETRY_V2 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1820] | IBM_SENSE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1829] | RQOVBLQO_JITTERBIT_AUDIT_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1830] | RQIHENBY_AIC_JIT_AUDIT_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1839] | ACN_SIA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1840] | ARCON_PAM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1843] | ARCDA_COREWEB |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1844] | IBM_SVA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1848] | AUTODESK_CAD_CAM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1850] | FORM3_SARIF |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1857] | BLUE_VOYANT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1858] | BBVA_MICROSTRATEGY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1864] | CAMEYO_ACTIVITY_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1872] | CISCO_VULNERABILITY_MANAGEMENT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1874] | CMMRZ_FORTI_DECEPTOR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1875] | CSG_CITRIX_RX |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1876] | EQIX_CONFIGURATION_BUILDER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1879] | D_STORMBREAKER_ALERTS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1880] | D_STORMBREAKER_AUDIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1891] | FA_SOLUTIONS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1892] | FILES_DOT_COM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1893] | FINCOMUN_ORACLE_SPEI |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1900] | GHANGOR_DLP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1905] | NETLIFY_LOGDRAINS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1916] | GDLP_ATLAS_USER_ELEVATION |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1922] | HSCR_ACCOUNTS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1923] | HILLSTONE_NGFW |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1924] | HOXHUNT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1926] | MC001_ELASTIC_CLICKS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1933] | INTEL_EMA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1939] | INDUSFACE_WAF |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1950] | MLL001_MOL_AGYIEUS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1951] | MLL001_MOL_SFTPGO |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1952] | MLL001_MOL_PCI_DC_CARDHOLDER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1953] | MLL001_MOL_PCI_DC_MANDATES |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1954] | MLL001_MOL_PCI_DC_SAD |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1955] | MLL001_MOL_PCI_DB_FIM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1956] | MLL001_MOL_PCI_GKE_FIM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1957] | MLL001_MOL_PCI_IIN_LOOKUP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1958] | MLL001_MOL_PCI_PCI_PROXY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1959] | MLL001_MOL_PCI_TOKENISER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1974] | PINGCAP_TIDB |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1975] | PLUMFINTECH_PLUM_SCA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1979] | PRIVACY_I |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1984] | JIRANSECURITY_MAILSCREEN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1985] | MY_RESOLVER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1986] | REVIVESEC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1989] | BRDCM_IMS_PAM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1990] | BBVA_BANKTRADE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1991] | BBVA_CONSORES |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1992] | RQTI0LIH_VERVE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1993] | RQTI0LIH_ONEHUB |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1994] | RQTI0LIH_EPI_MES |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1995] | WIZ_RUNTIME_EXECUTION_DATA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1996] | SAP_LEASING |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1997] | BBVA_SIRE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1998] | BBVA_POWER_CURVE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][1999] | BBVA_SMARTSTREAM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2000] | BBVA_SOLUCIONES |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2001] | BBVA_TEXSA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2002] | PAN_PRISMA_DIG_CLOUD_DSPM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2003] | BBVA_SIIBE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2004] | BBVA_MBOT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2005] | BBVA_SINBA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2006] | BBVA_MSDP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2007] | BBVA_PLUS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2008] | BBVA_CAIRO |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2009] | BBVA_SICOR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2010] | BBVA_FUMER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2011] | BBVA_MCOR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2012] | BBVA_MCWN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2013] | BBVA_ZEIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2014] | BBVA_CYGE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2015] | BBVA_SISP_NET |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2016] | BBVA_CLAIM_CENTER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2017] | BBVA_SAIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2018] | BBVA_SPWEB |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2019] | BBVA_VALIDADOR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2020] | BBVA_GUIA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2021] | BBVA_HECO |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2022] | GL_TRADE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2023] | ORACLE_AVDF |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2024] | REBLAZE_WAF |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2025] | VZ_MAXMIND_GEOIP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2026] | TT002_EXASOL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2027] | CORERO_SMARTWALL_ONE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2028] | AVEPOINT_ENPOWER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2029] | AVIGILON_AVA_SECURITY_CAMERA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2030] | GITHUB_DEPENDABOT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2031] | AWS_EKS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2032] | THALES_PS10K_HSM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2033] | F5_DCS_WAF |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2034] | CLOUDWAVE_HONEYPOT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2035] | PAN_PRISMA_CWP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2036] | FORTINET_FORTISASE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2037] | MICROSTRATEGY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2038] | AWS_DASHA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2039] | ONETRUST |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2040] | NETWRIX_PRIVILEGE_SECURE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2041] | SANGFOR_PROXY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2044] | SLSFR001_CSOC_SIEM_PLATFORM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2047] | SNF_SDH |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2052] | SOFTETHER_VPN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2055] | TLFNC003_TE_IDENTITY_ENTITY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2065] | UNICO_IDCLOUD |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2066] | UNICO_IDTRUST |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2085] | WING_SECURITY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2087] | WSGC_EGIFT_CARDS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2088] | ZERO_NETWORKS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2101] | JUNIPER_SSR_CONDUCTOR |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2102] | INFORMATICA_POWERCENTER |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2113] | EXTERRO_FTK_CENTRAL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2114] | CROWDSTRIKE_RECON |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2115] | CLOUDFLARE_PAGESHIELD |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2116] | FORTRA_VM |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2117] | GCP_CLOUD_ASSET_INVENTORY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2118] | RAPID_IDENTITY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2119] | SLSFR_VERTEX_IOC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2120] | ARCDA_VISTA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2121] | PRMTH_WSO2 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2122] | MC001_CLICKS_ENTERPAT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2123] | MC001_CLICKS_CLIUSERS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2124] | MC001_ROSHTOV_CLICKS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2125] | MC001_INFOSEC_BLOCK_TOOL |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2126] | MC001_MACCABI_PHARMACY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2127] | SPACELIFT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2128] | PAVE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2129] | MC001_MACCABI_NEW_APP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2130] | MC001_PORTAL_APPLICATION_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2131] | MC001_OFEK_EITAN |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2132] | MC001_MACCABI_ONLINE_SUPPORT_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2133] | MC001_MACCABI_ONLINE_LOGS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2134] | MC001_MACCABI_ONLINE_FAMILY |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2135] | CPS_JED_JCD_METRIC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2136] | H_ISAC |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2137] | IIJ_LANSCOPE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2138] | ML009_MENLO |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2429] | BBVA_CUSTODIA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2430] | BBVA_CREDIT_VW |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2431] | BBVA_CREDIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2494] | BBVA_WALLSTREET |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2496] | INFORMATICA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2737] | MT_APPLIED_PRINT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2756] | HANNA_KASEYA_IT_GLUE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2757] | KNRTH_COMMONFATE |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2759] | PARXL_MERAKI_CLOUD |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2763] | PRMTH_FIRSTIQ |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2764] | PRMTH_PWSS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2783] | RENAULT_IRN_74898 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2784] | RENAULT_IRN_73882 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2785] | RENAULT_IRN_72284 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2786] | RENAULT_IRN_74143 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2787] | RENAULT_IRN_70132 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2788] | RENAULT_IRN_50567 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2789] | RENAULT_IRN_8185 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2790] | RENAULT_IRN_77153 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2791] | RENAULT_IRN_67551 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2792] | RENAULT_IRN_73940 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2793] | RENAULT_IRN_75039 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2794] | RENAULT_IRN_69293 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2795] | RENAULT_IRN_74601 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2799] | RQ5XB66T_PINGCAP_TIDB_DB_AUDIT |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2812] | SML_SITEMINDER_PP |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2824] | SNF_FORENSIC_PREFETCH |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2825] | SNF_FORENSIC_HAYABUSA |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2864] | SHOPIFY_APV |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2882] | SHOPIFY_SVC_INT_2 |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2913] | VCTR727_AURUS |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2946] | WMT_GENAI |
|---|
| root['schemas']['IoCDiscoveryInfo']['properties']['logType']['enum'][2968] | WSGC_ECOM |
|---|
| root['schemas']['IoCStats']['properties']['iocStatsType']['enumDescriptions'][1] | IoCStat is from a Mandiant Source. |
|---|
| root['schemas']['IoCStats']['properties']['iocStatsType']['enumDescriptions'][2] | IoCStat is from a third-party source. |
|---|
| root['schemas']['IoCStats']['properties']['iocStatsType']['enumDescriptions'][3] | IoCStat is from a threat intelligence feed. |
|---|
| root['schemas']['IoCStats']['properties']['quality']['enumDescriptions'][1] | Low confidence. |
|---|
| root['schemas']['IoCStats']['properties']['quality']['enumDescriptions'][2] | Medium confidence. |
|---|
| root['schemas']['IoCStats']['properties']['quality']['enumDescriptions'][3] | High confidence. |
|---|
| root['schemas']['LegacyCase']['properties']['priority']['enumDescriptions'][1] | Informational priority. |
|---|
| root['schemas']['LegacyCase']['properties']['priority']['enumDescriptions'][2] | Low priority. |
|---|
| root['schemas']['LegacyCase']['properties']['priority']['enumDescriptions'][3] | Medium priority. |
|---|
| root['schemas']['LegacyCase']['properties']['priority']['enumDescriptions'][4] | High priority. |
|---|
| root['schemas']['LegacyCase']['properties']['priority']['enumDescriptions'][5] | Critical priority. |
|---|
| root['schemas']['LegacyCase']['properties']['status']['enumDescriptions'][1] | New finding. |
|---|
| root['schemas']['LegacyCase']['properties']['status']['enumDescriptions'][2] | When a finding has feedback. |
|---|
| root['schemas']['LegacyCase']['properties']['status']['enumDescriptions'][3] | When an analyst closes an finding. |
|---|
| root['schemas']['LegacyCase']['properties']['status']['enumDescriptions'][4] | Open. Used to indicate that a Case / Alert is open. |
|---|
| root['schemas']['LegacyFeedback']['properties']['priority']['enumDescriptions'][1] | Informational priority. |
|---|
| root['schemas']['LegacyFeedback']['properties']['priority']['enumDescriptions'][2] | Low priority. |
|---|
| root['schemas']['LegacyFeedback']['properties']['priority']['enumDescriptions'][3] | Medium priority. |
|---|
| root['schemas']['LegacyFeedback']['properties']['priority']['enumDescriptions'][4] | High priority. |
|---|
| root['schemas']['LegacyFeedback']['properties']['priority']['enumDescriptions'][5] | Critical priority. |
|---|
| root['schemas']['LegacyFeedback']['properties']['reason']['enumDescriptions'][1] | Case or Alert not malicious. |
|---|
| root['schemas']['LegacyFeedback']['properties']['reason']['enumDescriptions'][2] | Case or Alert is malicious. |
|---|
| root['schemas']['LegacyFeedback']['properties']['reason']['enumDescriptions'][3] | Case or Alert is under maintenance. |
|---|
| root['schemas']['LegacyFeedback']['properties']['reputation']['enumDescriptions'][1] | A categorization of the finding as useful. |
|---|
| root['schemas']['LegacyFeedback']['properties']['reputation']['enumDescriptions'][2] | A categorization of the finding as not useful. |
|---|
| root['schemas']['LegacyFeedback']['properties']['status']['enumDescriptions'][1] | New finding. |
|---|
| root['schemas']['LegacyFeedback']['properties']['status']['enumDescriptions'][2] | When a finding has feedback. |
|---|
| root['schemas']['LegacyFeedback']['properties']['status']['enumDescriptions'][3] | When an analyst closes an finding. |
|---|
| root['schemas']['LegacyFeedback']['properties']['status']['enumDescriptions'][4] | Open. Used to indicate that a Case / Alert is open. |
|---|
| root['schemas']['LegacyFeedback']['properties']['verdict']['enumDescriptions'][1] | A categorization of the finding as a "true positive". |
|---|
| root['schemas']['LegacyFeedback']['properties']['verdict']['enumDescriptions'][2] | A categorization of the finding as a "false positive". |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][1] | Allowed. |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][2] | Blocked. |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][3] | Strip, modify something (e.g. File or email was disinfected or rewritten and still forwarded). |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][4] | Put somewhere for later analysis (does NOT imply block). |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][5] | Failed (e.g. the event was allowed but failed). |
|---|
| root['schemas']['LegacyIocCuratedDetection']['properties']['deviceAction']['enumDescriptions'][6] | Challenged (e.g. the user was challenged by a Captcha, 2FA). |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][0] | An unspecified collection type. |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][1] | An alert reported in customer telemetry. |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][2] | A finding from the Uppercase team. |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][4] | A detection found by applying a rule. |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][5] | An alert generated by Chronicle machine learning models. |
|---|
| root['schemas']['MalachiteFinding']['properties']['findingType']['enumDescriptions'][6] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][1] | Ingested Raw telemetry |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][2] | Chronicle Rules engine |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][3] | Uppercase |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][4] | DSML - Machine Intelligence |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][5] | A normalized telemetry event from Google Security Command Center. |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][6] | Unspecified Namespace |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][7] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['MalachiteFinding']['properties']['uidNamespace']['enumDescriptions'][8] | VirusTotal. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][1] | Minimum. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][2] | Maximum. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][3] | Count. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][4] | Sum. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][5] | Average. |
|---|
| root['schemas']['Measure']['properties']['aggregateFunction']['enumDescriptions'][6] | Standard Deviation. |
|---|
| root['schemas']['Metadata']['properties']['enrichmentState']['enumDescriptions'][1] | The event has been enriched by Chronicle. |
|---|
| root['schemas']['Metadata']['properties']['enrichmentState']['enumDescriptions'][2] | The event has not been enriched by Chronicle. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][1] | Activity related to a process which does not match any other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][2] | Process launch. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][3] | Process injecting into another process. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][4] | Process privilege escalation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][5] | Process termination. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][6] | Process being opened. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][7] | Process loading a module. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][8] | Registry event which does not match any of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][9] | Registry creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][10] | Registry modification. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][11] | Registry deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][12] | Settings-related event which does not match any of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][13] | Setting creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][14] | Setting modification. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][15] | Setting deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][16] | Any mutex event other than creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][17] | Mutex creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][18] | File event which does not match any of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][19] | File created. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][20] | File deleted. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][21] | File modified. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][22] | File read. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][23] | File copied. Used for file copies, for example, to a thumb drive. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][24] | File opened. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][25] | File moved or renamed. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][26] | File synced (for example, Google Drive, Dropbox, backup). |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][27] | User activity which does not match any of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][28] | User login. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][29] | User logout. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][30] | User creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][31] | User password change event. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][32] | Change in user permissions. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][33] | Deprecated. Used to update user info for an LDAP dump. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][34] | User physically badging into a location. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][35] | User deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][36] | User creating a virtual resource. This is equivalent to RESOURCE_CREATION. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][37] | User updating content of a virtual resource. This is equivalent to RESOURCE_WRITTEN. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][38] | User updating permissions of a virtual resource. This is equivalent to RESOURCE_PERMISSIONS_CHANGE. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][39] | User initiating communication through a medium (for example, video). |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][40] | User accessing a virtual resource. This is equivalent to RESOURCE_READ. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][41] | User deleting a virtual resource. This is equivalent to RESOURCE_DELETION. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][42] | A group activity that does not fall into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][43] | A group creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][44] | A group deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][45] | A group modification. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][46] | Email messages |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][47] | An email transaction. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][48] | Deprecated: use NETWORK_HTTP instead. An email URL click event. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][49] | A network event that does not fit into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][50] | Aggregated flow stats like netflow. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][51] | Network connection details like from a FW. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][52] | FTP telemetry. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][53] | DHCP payload. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][54] | DNS payload. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][55] | HTTP telemetry. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][56] | SMTP telemetry. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][57] | A status message that does not fit into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][58] | Heartbeat indicating product is alive. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][59] | An agent startup. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][60] | An agent shutdown. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][61] | A software or fingerprint update. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][62] | Scan item that does not fit into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][63] | A file scan. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][64] | Scan process behaviors. Please use SCAN_PROCESS instead. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][65] | Scan process. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][66] | Scan results from scanning an entire host device for threats/sensitive documents. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][67] | Vulnerability scan logs about host vulnerabilities (e.g., out of date software) and network vulnerabilities (e.g., unprotected service detected via a network scan). |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][68] | Vulnerability scan logs about network vulnerabilities. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][69] | Scan network for suspicious activity |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][70] | Scheduled task event that does not fall into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][71] | Scheduled task creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][72] | Scheduled task deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][73] | Scheduled task being enabled. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][74] | Scheduled task being disabled. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][75] | Scheduled task being modified. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][76] | A system audit log event that is not a wipe. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][77] | A system audit log wipe. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][78] | Service event that does not fit into one of the other event types. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][79] | A service creation. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][80] | A service deletion. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][81] | A service start. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][82] | A service stop. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][83] | A service modification. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][84] | Operating system events that are not described by any of the other event types. Might include uncategorized Microsoft Windows event logs. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][85] | The resource was created/provisioned. This is equivalent to USER_RESOURCE_CREATION. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][86] | The resource was deleted/deprovisioned. This is equivalent to USER_RESOURCE_DELETION. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][87] | The resource had it's permissions or ACLs updated. This is equivalent to USER_RESOURCE_UPDATE_PERMISSIONS. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][88] | The resource was read. This is equivalent to USER_RESOURCE_ACCESS. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][89] | The resource was written to. This is equivalent to USER_RESOURCE_UPDATE_CONTENT. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][90] | Firmware update. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][91] | Configuration update. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][92] | A program or application uploaded to a device. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][93] | A program or application downloaded to a device. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][94] | Analyst update about the Verdict (such as true positive, false positive, or disregard) of a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][95] | Analyst update about the Reputation (such as useful or not useful) of a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][96] | Analyst update about the Severity score (0-100) of a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][97] | Analyst update about the finding status. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][98] | Analyst addition of a comment for a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][99] | Analyst update about the priority (such as low, medium, or high) for a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][100] | Analyst update about the root cause for a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][101] | Analyst update about the reason (such as malicious or not malicious) for a finding. |
|---|
| root['schemas']['Metadata']['properties']['eventType']['enumDescriptions'][102] | Analyst update about the risk score (0-100) of a finding. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][1] | Principal Device |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][2] | Target User |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][3] | Target Device |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][4] | Principal User |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][5] | Target IP |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][6] | Principal File Hash |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][7] | Principal Country |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][8] | Security Category |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][9] | Network ASN |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][10] | Client Certificate Hash |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][11] | DNS Query Type |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][12] | DNS Domain |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][13] | HTTP User Agent |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][14] | Event Type |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][15] | Product Name |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][16] | Product Event Type |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][17] | Parent Folder Path |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][18] | Target resource Name |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][19] | Principal Application. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][20] | Target Application. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][21] | Email To Address. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][22] | Email From Address. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][23] | Mail Id. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][24] | Principal IP. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][25] | Security Action. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][26] | Security Rule Id. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][27] | Target Network Organization name. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][28] | Principal Network Organization name. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][29] | Principal Process File Path. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][30] | Principal Process File SHA256 Hash. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][31] | Security Result rule name. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][32] | Target Resource label key. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][33] | Vendor name. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][34] | Target Resource type. |
|---|
| root['schemas']['Metric']['properties']['dimensions']['items']['enumDescriptions'][35] | Target Location name. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][1] | Total received network bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][2] | Total network sent bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][3] | Total network sent bytes and received bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][4] | Successful authentication attempts. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][5] | Failed authentication attempts. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][6] | Total authentication attempts. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][7] | Total number of sent bytes for DNS events. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][8] | Total number of events having non-null received bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][9] | Total number of events having non-null sent bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][10] | Total events having non-null sent or received bytes. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][11] | DNS query success count - Number of events with response_code = 0. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][12] | Number of events with response_code != 0. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][13] | Total number of DNS queries made. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][14] | Number of successfule file executions. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][15] | Number of failed file executions. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][16] | Total number file executions. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][17] | Number of successful HTTP queries. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][18] | Number of failed HTTP queries. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][19] | Total number of HTTP queries. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][20] | Total number of emails sent in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][21] | Total number of download actions in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][22] | Total number of change actions in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][23] | Total number of authentication attempts in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][24] | Number of outbound network bytes (total sent) in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][25] | Total number of network bytes (both sent and received) in Google Workspace. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][26] | Track number of alerts fired by EDR/SENTINEL/MICROSOFT_GRAPH. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][27] | First-time analytic tracking successful resource creations. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][28] | Volume-based analytic tracking successful resource creations. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][29] | Volume-based analytic tracking successful resource reads. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][30] | Volume-based analytic tracking failed resource reads. |
|---|
| root['schemas']['Metric']['properties']['metricName']['enumDescriptions'][31] | Volume-based analytic tracking successful resource deletions. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][1] | Apple Filing Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][2] | Advanced Program-to-Program Communication. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][3] | Advanced Message Queuing Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][4] | Publishing Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][5] | Block Extensible Exchange Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][6] | Crypto currency protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][7] | Peer-to-peer file sharing. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][8] | Coherent File Distribution Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][9] | Common Industrial Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][10] | Constrained Application Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][11] | Connection Oriented Transport Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][12] | DCE/RPC. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][13] | Data Distribution Service. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][14] | Automation industry protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][15] | DHCP. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][16] | Digital Imaging and Communications in Medicine Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][17] | Distributed Network Protocol 3 (DNP3) |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][18] | DNS. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][19] | Classic file sharing protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][20] | Endpoint Handlespace Redundancy Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][21] | Filesharing peer-to-peer protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][22] | User Information Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][23] | Censorship resistant peer-to-peer network. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][24] | File Transfer Access and Management. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][25] | GOOSE Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][26] | Gopher protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][27] | gRPC Remote Procedure Call. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][28] | Health Level Seven. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][29] | Packet-based multimedia communications system. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][30] | HTTP. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][31] | HTTPS. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][32] | IEC 60870-5-104 (IEC 104) Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][33] | Internet Relay Chat Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][34] | Peer-to-peer hashtables. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][35] | Kerberos 5. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][36] | Lightweight Directory Access Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][37] | Line Printer Daemon Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][38] | Multipurpose Internet Mail Extensions and Secure MIME. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][39] | Multimedia Messaging Service. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][40] | Serial communications protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][41] | Message Queuing Telemetry Transport. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][42] | Network Configuration. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][43] | Network File System. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][44] | Network Information Service. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][45] | Network News Transfer Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][46] | National Transportation Communications for Intelligent Transportation System. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][47] | Network Time Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][48] | AOL Instant Messenger Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][49] | Peer Name Resolution Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][50] | Precision Time Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][51] | QUIC. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][52] | Remote Desktop Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][53] | Reliable Event Logging Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][54] | Routing Information Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][55] | Remote Login in UNIX Systems. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][56] | Remote Procedure Call. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][57] | Real Time Messaging Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][58] | Real-time Transport Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][59] | Real Time Publish Subscribe. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][60] | Real Time Streaming Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][61] | Session Announcement Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][62] | Session Description Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][63] | Session Initiation Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][64] | Service Location Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][65] | Server Message Block. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][66] | Simple Mail Transfer Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][67] | Simple Network Management Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][68] | Simple Network Time Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][69] | Secure Shell. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][70] | Secure SMS Messaging Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][71] | Styx/9P - Plan 9 from Bell Labs distributed file system protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][72] | Sampled Values Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][73] | Transaction Capabilities Application Part. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][74] | Tabular Data Stream. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][75] | Anonymity network. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][76] | Time Stamp Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][77] | Virtual Terminal Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][78] | Remote Directory Access Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][79] | Web Distributed Authoring and Versioning. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][80] | Message Handling Service Protocol. |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][81] | Directory Access Protocol (DAP). |
|---|
| root['schemas']['Network']['properties']['applicationProtocol']['enumDescriptions'][82] | Extensible Messaging and Presence Protocol. |
|---|
| root['schemas']['Network']['properties']['direction']['enumDescriptions'][1] | An inbound request. |
|---|
| root['schemas']['Network']['properties']['direction']['enumDescriptions'][2] | An outbound request. |
|---|
| root['schemas']['Network']['properties']['direction']['enumDescriptions'][3] | A broadcast. |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][1] | ICMP. |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][2] | IGMP |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][3] | TCP. |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][4] | UDP. |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][5] | IPv6 Encapsulation |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][6] | Generic Routing Encapsulation |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][7] | Encapsulating Security Payload |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][8] | ICMPv6 |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][9] | Enhanced Interior Gateway Routing |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][10] | Ethernet-within-IP Encapsulation |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][11] | Protocol Independent Multicast |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][12] | Virtual Router Redundancy Protocol |
|---|
| root['schemas']['Network']['properties']['ipProtocol']['enumDescriptions'][13] | Stream Control Transmission Protocol |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][1] | Microsoft Windows. |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][2] | macOS. |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][3] | Linux. |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][4] | Deprecated: see cloud.environment. |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][7] | IOS |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][8] | Android |
|---|
| root['schemas']['Noun']['properties']['platform']['enumDescriptions'][9] | Chrome OS |
|---|
| root['schemas']['Permission']['properties']['type']['enumDescriptions'][1] | Administrator write permission. |
|---|
| root['schemas']['Permission']['properties']['type']['enumDescriptions'][2] | Administrator read permission. |
|---|
| root['schemas']['Permission']['properties']['type']['enumDescriptions'][3] | Data resource access write permission. |
|---|
| root['schemas']['Permission']['properties']['type']['enumDescriptions'][4] | Data resource access read permission. |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][1] | Microsoft Windows. |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][2] | macOS. |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][3] | Linux. |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][4] | Deprecated: see cloud.environment. |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][7] | IOS |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][8] | Android |
|---|
| root['schemas']['PlatformSoftware']['properties']['platform']['enumDescriptions'][9] | Chrome OS |
|---|
| root['schemas']['PriorityCount']['properties']['priority']['enumDescriptions'][1] | Informational priority. |
|---|
| root['schemas']['PriorityCount']['properties']['priority']['enumDescriptions'][2] | Low priority. |
|---|
| root['schemas']['PriorityCount']['properties']['priority']['enumDescriptions'][3] | Medium priority. |
|---|
| root['schemas']['PriorityCount']['properties']['priority']['enumDescriptions'][4] | High priority. |
|---|
| root['schemas']['PriorityCount']['properties']['priority']['enumDescriptions'][5] | Critical priority. |
|---|
| root['schemas']['Process']['properties']['tokenElevationType']['enumDescriptions'][1] | A full token with no privileges removed or groups disabled. |
|---|
| root['schemas']['Process']['properties']['tokenElevationType']['enumDescriptions'][2] | An elevated token with no privileges removed or groups disabled. Used when running as administrator. |
|---|
| root['schemas']['Process']['properties']['tokenElevationType']['enumDescriptions'][3] | A limited token with administrative privileges removed and administrative groups disabled. |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][90] | TRENDMICRO_CLOUD_EMAIL_GATEWAY_PROTECTION |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][91] | FRONT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][92] | DBDEV_ZOOM_ACTIVITY_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][94] | VUHL_SO_IDH |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][95] | AWS_LAMBDA_FUNCTION |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][96] | MASMOVIL_GENERIC_CSV_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][97] | MASMOVIL_GENERIC_JSON_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][98] | MASMOVIL_GENERIC_SYSLOG_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][99] | MASMOVIL_GENERIC_KV_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][100] | MASMOVIL_GENERIC_XML_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][101] | MASMOVIL_GENERIC_SYSLOGKV_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][102] | MASMOVIL_GENERIC_SYSLOGJSON_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][103] | MASMOVIL_GENERIC_SYSLOGXML_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][104] | MASMOVIL_GENERIC_LEEF_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][105] | MASMOVIL_GENERIC_CEF_1 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][221] | TEHTRIS_EDR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][222] | PLUMFINTECH_PLUM_BACKOFFICE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][223] | GCLDW_CLODWAVE_HIDS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][243] | CYNERIO_NDR_H |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][282] | WIREGUARD_VPN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][290] | CLAVISTER_FIREWALL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][427] | PROOFPOINT_IDENTITY_THREAT_PLATFORM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][467] | VICARIUS_VRX_EVENTS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][603] | FORTINET_ADC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][622] | HUAWEI_WIRELESS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][627] | AZURE_VNET_FLOW |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][629] | CISCO_NETFLOW |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][641] | BELDEN_SWITCH |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][666] | HP_ROUTER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][681] | VELOCLOUD_SDWAN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][708] | TRENDMICRO_VISION_ONE_ACTIVITY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][709] | TRENDMICRO_VISION_ONE_DETECTIONS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][710] | TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][745] | TRELLIX_HX_AUDIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][807] | RAVEN_DB |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][827] | AZURE_RISKY_USERS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][828] | AZURE_RISK_EVENTS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][829] | AZURE_SERVICE_PRINCIPAL_LOGINS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][859] | D_OPENPATH_CONTEXT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][873] | CIP_FASTWEB_IOC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][947] | SOLIDSERVER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][990] | HLX_FASTWEB_LOG |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][991] | CMB_FASTWEB_LOG |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1013] | WFA_FASTWEB_LOG |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1020] | PINGONE_AIC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1021] | PINGONE_PROTECT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1129] | FRCPT_FORCEPOINT_MAILCONTROL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1130] | FOXPASS_AUDIT_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1131] | DRAYTEK_ROUTER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1132] | CHROMEOS_XDR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1133] | VECTRA_XDR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1134] | METABASE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1135] | HUAWEI_FUSIONSPHERE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1136] | HUAWEI_FIREWALL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1281] | MY_SAILPOINT_LIFECYCLE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1366] | ONEIDENTITY_SAFEGUARD |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1399] | CLICKHOUSE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1422] | JOBLOGIC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1461] | ZOHO_ASSIST |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1483] | OPENTEXT_CORDY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1526] | CLOUDFLARE_NETWORK_ANALYTICS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1556] | CROWDSTRIKE_DLP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1625] | JAMF_TELEMETRY_V2 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1820] | IBM_SENSE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1829] | RQOVBLQO_JITTERBIT_AUDIT_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1830] | RQIHENBY_AIC_JIT_AUDIT_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1839] | ACN_SIA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1840] | ARCON_PAM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1843] | ARCDA_COREWEB |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1844] | IBM_SVA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1848] | AUTODESK_CAD_CAM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1850] | FORM3_SARIF |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1857] | BLUE_VOYANT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1858] | BBVA_MICROSTRATEGY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1864] | CAMEYO_ACTIVITY_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1872] | CISCO_VULNERABILITY_MANAGEMENT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1874] | CMMRZ_FORTI_DECEPTOR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1875] | CSG_CITRIX_RX |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1876] | EQIX_CONFIGURATION_BUILDER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1879] | D_STORMBREAKER_ALERTS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1880] | D_STORMBREAKER_AUDIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1891] | FA_SOLUTIONS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1892] | FILES_DOT_COM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1893] | FINCOMUN_ORACLE_SPEI |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1900] | GHANGOR_DLP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1905] | NETLIFY_LOGDRAINS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1916] | GDLP_ATLAS_USER_ELEVATION |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1922] | HSCR_ACCOUNTS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1923] | HILLSTONE_NGFW |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1924] | HOXHUNT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1926] | MC001_ELASTIC_CLICKS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1933] | INTEL_EMA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1939] | INDUSFACE_WAF |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1950] | MLL001_MOL_AGYIEUS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1951] | MLL001_MOL_SFTPGO |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1952] | MLL001_MOL_PCI_DC_CARDHOLDER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1953] | MLL001_MOL_PCI_DC_MANDATES |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1954] | MLL001_MOL_PCI_DC_SAD |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1955] | MLL001_MOL_PCI_DB_FIM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1956] | MLL001_MOL_PCI_GKE_FIM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1957] | MLL001_MOL_PCI_IIN_LOOKUP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1958] | MLL001_MOL_PCI_PCI_PROXY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1959] | MLL001_MOL_PCI_TOKENISER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1974] | PINGCAP_TIDB |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1975] | PLUMFINTECH_PLUM_SCA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1979] | PRIVACY_I |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1984] | JIRANSECURITY_MAILSCREEN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1985] | MY_RESOLVER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1986] | REVIVESEC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1989] | BRDCM_IMS_PAM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1990] | BBVA_BANKTRADE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1991] | BBVA_CONSORES |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1992] | RQTI0LIH_VERVE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1993] | RQTI0LIH_ONEHUB |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1994] | RQTI0LIH_EPI_MES |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1995] | WIZ_RUNTIME_EXECUTION_DATA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1996] | SAP_LEASING |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1997] | BBVA_SIRE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1998] | BBVA_POWER_CURVE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][1999] | BBVA_SMARTSTREAM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2000] | BBVA_SOLUCIONES |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2001] | BBVA_TEXSA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2002] | PAN_PRISMA_DIG_CLOUD_DSPM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2003] | BBVA_SIIBE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2004] | BBVA_MBOT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2005] | BBVA_SINBA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2006] | BBVA_MSDP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2007] | BBVA_PLUS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2008] | BBVA_CAIRO |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2009] | BBVA_SICOR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2010] | BBVA_FUMER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2011] | BBVA_MCOR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2012] | BBVA_MCWN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2013] | BBVA_ZEIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2014] | BBVA_CYGE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2015] | BBVA_SISP_NET |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2016] | BBVA_CLAIM_CENTER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2017] | BBVA_SAIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2018] | BBVA_SPWEB |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2019] | BBVA_VALIDADOR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2020] | BBVA_GUIA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2021] | BBVA_HECO |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2022] | GL_TRADE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2023] | ORACLE_AVDF |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2024] | REBLAZE_WAF |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2025] | VZ_MAXMIND_GEOIP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2026] | TT002_EXASOL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2027] | CORERO_SMARTWALL_ONE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2028] | AVEPOINT_ENPOWER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2029] | AVIGILON_AVA_SECURITY_CAMERA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2030] | GITHUB_DEPENDABOT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2031] | AWS_EKS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2032] | THALES_PS10K_HSM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2033] | F5_DCS_WAF |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2034] | CLOUDWAVE_HONEYPOT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2035] | PAN_PRISMA_CWP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2036] | FORTINET_FORTISASE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2037] | MICROSTRATEGY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2038] | AWS_DASHA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2039] | ONETRUST |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2040] | NETWRIX_PRIVILEGE_SECURE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2041] | SANGFOR_PROXY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2044] | SLSFR001_CSOC_SIEM_PLATFORM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2047] | SNF_SDH |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2052] | SOFTETHER_VPN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2055] | TLFNC003_TE_IDENTITY_ENTITY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2065] | UNICO_IDCLOUD |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2066] | UNICO_IDTRUST |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2085] | WING_SECURITY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2087] | WSGC_EGIFT_CARDS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2088] | ZERO_NETWORKS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2101] | JUNIPER_SSR_CONDUCTOR |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2102] | INFORMATICA_POWERCENTER |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2113] | EXTERRO_FTK_CENTRAL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2114] | CROWDSTRIKE_RECON |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2115] | CLOUDFLARE_PAGESHIELD |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2116] | FORTRA_VM |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2117] | GCP_CLOUD_ASSET_INVENTORY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2118] | RAPID_IDENTITY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2119] | SLSFR_VERTEX_IOC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2120] | ARCDA_VISTA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2121] | PRMTH_WSO2 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2122] | MC001_CLICKS_ENTERPAT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2123] | MC001_CLICKS_CLIUSERS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2124] | MC001_ROSHTOV_CLICKS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2125] | MC001_INFOSEC_BLOCK_TOOL |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2126] | MC001_MACCABI_PHARMACY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2127] | SPACELIFT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2128] | PAVE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2129] | MC001_MACCABI_NEW_APP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2130] | MC001_PORTAL_APPLICATION_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2131] | MC001_OFEK_EITAN |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2132] | MC001_MACCABI_ONLINE_SUPPORT_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2133] | MC001_MACCABI_ONLINE_LOGS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2134] | MC001_MACCABI_ONLINE_FAMILY |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2135] | CPS_JED_JCD_METRIC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2136] | H_ISAC |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2137] | IIJ_LANSCOPE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2138] | ML009_MENLO |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2429] | BBVA_CUSTODIA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2430] | BBVA_CREDIT_VW |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2431] | BBVA_CREDIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2494] | BBVA_WALLSTREET |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2496] | INFORMATICA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2737] | MT_APPLIED_PRINT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2756] | HANNA_KASEYA_IT_GLUE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2757] | KNRTH_COMMONFATE |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2759] | PARXL_MERAKI_CLOUD |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2763] | PRMTH_FIRSTIQ |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2764] | PRMTH_PWSS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2783] | RENAULT_IRN_74898 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2784] | RENAULT_IRN_73882 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2785] | RENAULT_IRN_72284 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2786] | RENAULT_IRN_74143 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2787] | RENAULT_IRN_70132 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2788] | RENAULT_IRN_50567 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2789] | RENAULT_IRN_8185 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2790] | RENAULT_IRN_77153 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2791] | RENAULT_IRN_67551 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2792] | RENAULT_IRN_73940 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2793] | RENAULT_IRN_75039 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2794] | RENAULT_IRN_69293 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2795] | RENAULT_IRN_74601 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2799] | RQ5XB66T_PINGCAP_TIDB_DB_AUDIT |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2812] | SML_SITEMINDER_PP |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2824] | SNF_FORENSIC_PREFETCH |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2825] | SNF_FORENSIC_HAYABUSA |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2864] | SHOPIFY_APV |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2882] | SHOPIFY_SVC_INT_2 |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2913] | VCTR727_AURUS |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2946] | WMT_GENAI |
|---|
| root['schemas']['RawLog']['properties']['type']['enum'][2968] | WSGC_ECOM |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][1] | Activity related to a process which does not match any other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][2] | Process launch. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][3] | Process injecting into another process. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][4] | Process privilege escalation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][5] | Process termination. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][6] | Process being opened. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][7] | Process loading a module. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][8] | Registry event which does not match any of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][9] | Registry creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][10] | Registry modification. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][11] | Registry deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][12] | Settings-related event which does not match any of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][13] | Setting creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][14] | Setting modification. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][15] | Setting deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][16] | Any mutex event other than creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][17] | Mutex creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][18] | File event which does not match any of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][19] | File created. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][20] | File deleted. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][21] | File modified. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][22] | File read. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][23] | File copied. Used for file copies, for example, to a thumb drive. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][24] | File opened. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][25] | File moved or renamed. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][26] | File synced (for example, Google Drive, Dropbox, backup). |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][27] | User activity which does not match any of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][28] | User login. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][29] | User logout. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][30] | User creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][31] | User password change event. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][32] | Change in user permissions. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][33] | Deprecated. Used to update user info for an LDAP dump. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][34] | User physically badging into a location. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][35] | User deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][36] | User creating a virtual resource. This is equivalent to RESOURCE_CREATION. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][37] | User updating content of a virtual resource. This is equivalent to RESOURCE_WRITTEN. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][38] | User updating permissions of a virtual resource. This is equivalent to RESOURCE_PERMISSIONS_CHANGE. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][39] | User initiating communication through a medium (for example, video). |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][40] | User accessing a virtual resource. This is equivalent to RESOURCE_READ. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][41] | User deleting a virtual resource. This is equivalent to RESOURCE_DELETION. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][42] | A group activity that does not fall into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][43] | A group creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][44] | A group deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][45] | A group modification. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][46] | Email messages |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][47] | An email transaction. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][48] | Deprecated: use NETWORK_HTTP instead. An email URL click event. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][49] | A network event that does not fit into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][50] | Aggregated flow stats like netflow. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][51] | Network connection details like from a FW. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][52] | FTP telemetry. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][53] | DHCP payload. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][54] | DNS payload. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][55] | HTTP telemetry. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][56] | SMTP telemetry. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][57] | A status message that does not fit into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][58] | Heartbeat indicating product is alive. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][59] | An agent startup. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][60] | An agent shutdown. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][61] | A software or fingerprint update. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][62] | Scan item that does not fit into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][63] | A file scan. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][64] | Scan process behaviors. Please use SCAN_PROCESS instead. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][65] | Scan process. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][66] | Scan results from scanning an entire host device for threats/sensitive documents. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][67] | Vulnerability scan logs about host vulnerabilities (e.g., out of date software) and network vulnerabilities (e.g., unprotected service detected via a network scan). |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][68] | Vulnerability scan logs about network vulnerabilities. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][69] | Scan network for suspicious activity |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][70] | Scheduled task event that does not fall into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][71] | Scheduled task creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][72] | Scheduled task deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][73] | Scheduled task being enabled. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][74] | Scheduled task being disabled. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][75] | Scheduled task being modified. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][76] | A system audit log event that is not a wipe. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][77] | A system audit log wipe. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][78] | Service event that does not fit into one of the other event types. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][79] | A service creation. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][80] | A service deletion. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][81] | A service start. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][82] | A service stop. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][83] | A service modification. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][84] | Operating system events that are not described by any of the other event types. Might include uncategorized Microsoft Windows event logs. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][85] | The resource was created/provisioned. This is equivalent to USER_RESOURCE_CREATION. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][86] | The resource was deleted/deprovisioned. This is equivalent to USER_RESOURCE_DELETION. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][87] | The resource had it's permissions or ACLs updated. This is equivalent to USER_RESOURCE_UPDATE_PERMISSIONS. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][88] | The resource was read. This is equivalent to USER_RESOURCE_ACCESS. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][89] | The resource was written to. This is equivalent to USER_RESOURCE_UPDATE_CONTENT. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][90] | Firmware update. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][91] | Configuration update. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][92] | A program or application uploaded to a device. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][93] | A program or application downloaded to a device. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][94] | Analyst update about the Verdict (such as true positive, false positive, or disregard) of a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][95] | Analyst update about the Reputation (such as useful or not useful) of a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][96] | Analyst update about the Severity score (0-100) of a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][97] | Analyst update about the finding status. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][98] | Analyst addition of a comment for a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][99] | Analyst update about the priority (such as low, medium, or high) for a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][100] | Analyst update about the root cause for a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][101] | Analyst update about the reason (such as malicious or not malicious) for a finding. |
|---|
| root['schemas']['RawLogEventInformation']['properties']['eventType']['enumDescriptions'][102] | Analyst update about the risk score (0-100) of a finding. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][1] | The registry value is not set and only the key exists. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][2] | A null-terminated string. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][3] | A null-terminated string that contains unexpanded references to environment variables |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][4] | Binary data in any form. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][5] | A 32-bit number. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][6] | A 32-bit number in little-endian format. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][7] | A 32-bit number in big-endian format. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][8] | A null-terminated Unicode string that contains the target path of a symbolic link. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][9] | A sequence of null-terminated strings, terminated by an empty string |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][10] | A device driver resource list. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][11] | A 64-bit number. |
|---|
| root['schemas']['Registry']['properties']['registryValueType']['enumDescriptions'][12] | A 64-bit number in little-endian format. |
|---|
| root['schemas']['Relation']['properties']['direction']['enumDescriptions'][1] | Modeled in both directions. Primary entity (a) to related entity (b) and related entity (b) to primary entity (a). |
|---|
| root['schemas']['Relation']['properties']['direction']['enumDescriptions'][2] | Modeled in a single direction. Primary entity (a) to related entity (b). |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][1] | The Noun represents a principal type object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][2] | The Noun represents a target type object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][3] | The Noun represents an observer type object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][4] | The Noun represents src type object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][5] | The Noun represents a network type object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][6] | The Noun represents a SecurityResult object. |
|---|
| root['schemas']['Relation']['properties']['entityLabel']['enumDescriptions'][7] | The Noun represents an intermediary type object. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][1] | An asset, such as workstation, laptop, phone, virtual machine, etc. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][2] | User. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][3] | Group. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][4] | Resource. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][5] | An external IP address. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][6] | A file. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][7] | A domain. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][8] | A url. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][9] | A mutex. |
|---|
| root['schemas']['Relation']['properties']['entityType']['enumDescriptions'][10] | A metric. |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][1] | Related entity is owned by the primary entity (e.g. user owns device asset). |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][2] | Related entity is administered by the primary entity (e.g. user administers a group). |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][3] | Primary entity is a member of the related entity (e.g. user is a member of a group). |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][4] | Primary entity may have executed the related entity. |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][5] | Primary entity may have been downloaded from the related entity. |
|---|
| root['schemas']['Relation']['properties']['relationship']['enumDescriptions'][6] | Primary entity contacts the related entity. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][1] | Mutex. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][2] | Task. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][3] | Named pipe. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][4] | Device. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][5] | Firewall rule. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][6] | Mailbox folder. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][7] | VPC Network. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][8] | Virtual machine. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][9] | Storage bucket. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][10] | Storage object. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][11] | Database. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][12] | Data table. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][13] | Cloud project. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][14] | Cloud organization. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][15] | Service account. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][16] | Access policy. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][17] | Cluster. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][18] | Settings. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][19] | Dataset. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][20] | Endpoint that receive traffic from a load balancer or proxy. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][21] | Pod, which is a collection of containers. Often used in Kubernetes. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][22] | Container. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][23] | Cloud function. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][24] | Runtime. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][25] | IP address. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][26] | Disk. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][27] | Volume. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][28] | Machine image. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][29] | Snapshot. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][30] | Repository. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][31] | Credential, e.g. access keys, ssh keys, tokens, certificates. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][32] | Load balancer. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][33] | Gateway. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][34] | Subnet. |
|---|
| root['schemas']['Resource']['properties']['resourceType']['enumDescriptions'][35] | User. |
|---|
| root['schemas']['ResponsePlatformInfo']['properties']['responsePlatformType']['enumDescriptions'][1] | Siemplify |
|---|
| root['schemas']['Role']['properties']['type']['enumDescriptions'][1] | Product administrator with elevated privileges. |
|---|
| root['schemas']['Role']['properties']['type']['enumDescriptions'][2] | System service account for automated privilege access. |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][90] | TRENDMICRO_CLOUD_EMAIL_GATEWAY_PROTECTION |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][91] | FRONT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][92] | DBDEV_ZOOM_ACTIVITY_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][94] | VUHL_SO_IDH |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][95] | AWS_LAMBDA_FUNCTION |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][96] | MASMOVIL_GENERIC_CSV_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][97] | MASMOVIL_GENERIC_JSON_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][98] | MASMOVIL_GENERIC_SYSLOG_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][99] | MASMOVIL_GENERIC_KV_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][100] | MASMOVIL_GENERIC_XML_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][101] | MASMOVIL_GENERIC_SYSLOGKV_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][102] | MASMOVIL_GENERIC_SYSLOGJSON_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][103] | MASMOVIL_GENERIC_SYSLOGXML_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][104] | MASMOVIL_GENERIC_LEEF_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][105] | MASMOVIL_GENERIC_CEF_1 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][221] | TEHTRIS_EDR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][222] | PLUMFINTECH_PLUM_BACKOFFICE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][223] | GCLDW_CLODWAVE_HIDS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][243] | CYNERIO_NDR_H |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][282] | WIREGUARD_VPN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][290] | CLAVISTER_FIREWALL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][427] | PROOFPOINT_IDENTITY_THREAT_PLATFORM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][467] | VICARIUS_VRX_EVENTS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][603] | FORTINET_ADC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][622] | HUAWEI_WIRELESS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][627] | AZURE_VNET_FLOW |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][629] | CISCO_NETFLOW |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][641] | BELDEN_SWITCH |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][666] | HP_ROUTER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][681] | VELOCLOUD_SDWAN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][708] | TRENDMICRO_VISION_ONE_ACTIVITY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][709] | TRENDMICRO_VISION_ONE_DETECTIONS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][710] | TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][745] | TRELLIX_HX_AUDIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][807] | RAVEN_DB |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][827] | AZURE_RISKY_USERS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][828] | AZURE_RISK_EVENTS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][829] | AZURE_SERVICE_PRINCIPAL_LOGINS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][859] | D_OPENPATH_CONTEXT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][873] | CIP_FASTWEB_IOC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][947] | SOLIDSERVER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][990] | HLX_FASTWEB_LOG |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][991] | CMB_FASTWEB_LOG |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1013] | WFA_FASTWEB_LOG |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1020] | PINGONE_AIC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1021] | PINGONE_PROTECT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1129] | FRCPT_FORCEPOINT_MAILCONTROL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1130] | FOXPASS_AUDIT_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1131] | DRAYTEK_ROUTER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1132] | CHROMEOS_XDR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1133] | VECTRA_XDR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1134] | METABASE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1135] | HUAWEI_FUSIONSPHERE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1136] | HUAWEI_FIREWALL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1281] | MY_SAILPOINT_LIFECYCLE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1366] | ONEIDENTITY_SAFEGUARD |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1399] | CLICKHOUSE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1422] | JOBLOGIC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1461] | ZOHO_ASSIST |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1483] | OPENTEXT_CORDY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1526] | CLOUDFLARE_NETWORK_ANALYTICS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1556] | CROWDSTRIKE_DLP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1625] | JAMF_TELEMETRY_V2 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1820] | IBM_SENSE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1829] | RQOVBLQO_JITTERBIT_AUDIT_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1830] | RQIHENBY_AIC_JIT_AUDIT_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1839] | ACN_SIA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1840] | ARCON_PAM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1843] | ARCDA_COREWEB |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1844] | IBM_SVA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1848] | AUTODESK_CAD_CAM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1850] | FORM3_SARIF |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1857] | BLUE_VOYANT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1858] | BBVA_MICROSTRATEGY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1864] | CAMEYO_ACTIVITY_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1872] | CISCO_VULNERABILITY_MANAGEMENT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1874] | CMMRZ_FORTI_DECEPTOR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1875] | CSG_CITRIX_RX |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1876] | EQIX_CONFIGURATION_BUILDER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1879] | D_STORMBREAKER_ALERTS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1880] | D_STORMBREAKER_AUDIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1891] | FA_SOLUTIONS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1892] | FILES_DOT_COM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1893] | FINCOMUN_ORACLE_SPEI |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1900] | GHANGOR_DLP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1905] | NETLIFY_LOGDRAINS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1916] | GDLP_ATLAS_USER_ELEVATION |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1922] | HSCR_ACCOUNTS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1923] | HILLSTONE_NGFW |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1924] | HOXHUNT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1926] | MC001_ELASTIC_CLICKS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1933] | INTEL_EMA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1939] | INDUSFACE_WAF |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1950] | MLL001_MOL_AGYIEUS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1951] | MLL001_MOL_SFTPGO |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1952] | MLL001_MOL_PCI_DC_CARDHOLDER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1953] | MLL001_MOL_PCI_DC_MANDATES |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1954] | MLL001_MOL_PCI_DC_SAD |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1955] | MLL001_MOL_PCI_DB_FIM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1956] | MLL001_MOL_PCI_GKE_FIM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1957] | MLL001_MOL_PCI_IIN_LOOKUP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1958] | MLL001_MOL_PCI_PCI_PROXY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1959] | MLL001_MOL_PCI_TOKENISER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1974] | PINGCAP_TIDB |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1975] | PLUMFINTECH_PLUM_SCA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1979] | PRIVACY_I |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1984] | JIRANSECURITY_MAILSCREEN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1985] | MY_RESOLVER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1986] | REVIVESEC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1989] | BRDCM_IMS_PAM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1990] | BBVA_BANKTRADE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1991] | BBVA_CONSORES |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1992] | RQTI0LIH_VERVE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1993] | RQTI0LIH_ONEHUB |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1994] | RQTI0LIH_EPI_MES |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1995] | WIZ_RUNTIME_EXECUTION_DATA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1996] | SAP_LEASING |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1997] | BBVA_SIRE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1998] | BBVA_POWER_CURVE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][1999] | BBVA_SMARTSTREAM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2000] | BBVA_SOLUCIONES |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2001] | BBVA_TEXSA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2002] | PAN_PRISMA_DIG_CLOUD_DSPM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2003] | BBVA_SIIBE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2004] | BBVA_MBOT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2005] | BBVA_SINBA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2006] | BBVA_MSDP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2007] | BBVA_PLUS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2008] | BBVA_CAIRO |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2009] | BBVA_SICOR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2010] | BBVA_FUMER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2011] | BBVA_MCOR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2012] | BBVA_MCWN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2013] | BBVA_ZEIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2014] | BBVA_CYGE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2015] | BBVA_SISP_NET |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2016] | BBVA_CLAIM_CENTER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2017] | BBVA_SAIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2018] | BBVA_SPWEB |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2019] | BBVA_VALIDADOR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2020] | BBVA_GUIA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2021] | BBVA_HECO |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2022] | GL_TRADE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2023] | ORACLE_AVDF |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2024] | REBLAZE_WAF |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2025] | VZ_MAXMIND_GEOIP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2026] | TT002_EXASOL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2027] | CORERO_SMARTWALL_ONE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2028] | AVEPOINT_ENPOWER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2029] | AVIGILON_AVA_SECURITY_CAMERA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2030] | GITHUB_DEPENDABOT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2031] | AWS_EKS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2032] | THALES_PS10K_HSM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2033] | F5_DCS_WAF |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2034] | CLOUDWAVE_HONEYPOT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2035] | PAN_PRISMA_CWP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2036] | FORTINET_FORTISASE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2037] | MICROSTRATEGY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2038] | AWS_DASHA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2039] | ONETRUST |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2040] | NETWRIX_PRIVILEGE_SECURE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2041] | SANGFOR_PROXY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2044] | SLSFR001_CSOC_SIEM_PLATFORM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2047] | SNF_SDH |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2052] | SOFTETHER_VPN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2055] | TLFNC003_TE_IDENTITY_ENTITY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2065] | UNICO_IDCLOUD |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2066] | UNICO_IDTRUST |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2085] | WING_SECURITY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2087] | WSGC_EGIFT_CARDS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2088] | ZERO_NETWORKS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2101] | JUNIPER_SSR_CONDUCTOR |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2102] | INFORMATICA_POWERCENTER |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2113] | EXTERRO_FTK_CENTRAL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2114] | CROWDSTRIKE_RECON |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2115] | CLOUDFLARE_PAGESHIELD |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2116] | FORTRA_VM |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2117] | GCP_CLOUD_ASSET_INVENTORY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2118] | RAPID_IDENTITY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2119] | SLSFR_VERTEX_IOC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2120] | ARCDA_VISTA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2121] | PRMTH_WSO2 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2122] | MC001_CLICKS_ENTERPAT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2123] | MC001_CLICKS_CLIUSERS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2124] | MC001_ROSHTOV_CLICKS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2125] | MC001_INFOSEC_BLOCK_TOOL |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2126] | MC001_MACCABI_PHARMACY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2127] | SPACELIFT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2128] | PAVE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2129] | MC001_MACCABI_NEW_APP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2130] | MC001_PORTAL_APPLICATION_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2131] | MC001_OFEK_EITAN |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2132] | MC001_MACCABI_ONLINE_SUPPORT_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2133] | MC001_MACCABI_ONLINE_LOGS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2134] | MC001_MACCABI_ONLINE_FAMILY |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2135] | CPS_JED_JCD_METRIC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2136] | H_ISAC |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2137] | IIJ_LANSCOPE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2138] | ML009_MENLO |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2429] | BBVA_CUSTODIA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2430] | BBVA_CREDIT_VW |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2431] | BBVA_CREDIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2494] | BBVA_WALLSTREET |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2496] | INFORMATICA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2737] | MT_APPLIED_PRINT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2756] | HANNA_KASEYA_IT_GLUE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2757] | KNRTH_COMMONFATE |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2759] | PARXL_MERAKI_CLOUD |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2763] | PRMTH_FIRSTIQ |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2764] | PRMTH_PWSS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2783] | RENAULT_IRN_74898 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2784] | RENAULT_IRN_73882 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2785] | RENAULT_IRN_72284 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2786] | RENAULT_IRN_74143 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2787] | RENAULT_IRN_70132 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2788] | RENAULT_IRN_50567 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2789] | RENAULT_IRN_8185 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2790] | RENAULT_IRN_77153 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2791] | RENAULT_IRN_67551 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2792] | RENAULT_IRN_73940 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2793] | RENAULT_IRN_75039 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2794] | RENAULT_IRN_69293 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2795] | RENAULT_IRN_74601 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2799] | RQ5XB66T_PINGCAP_TIDB_DB_AUDIT |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2812] | SML_SITEMINDER_PP |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2824] | SNF_FORENSIC_PREFETCH |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2825] | SNF_FORENSIC_HAYABUSA |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2864] | SHOPIFY_APV |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2882] | SHOPIFY_SVC_INT_2 |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2913] | VCTR727_AURUS |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2946] | WMT_GENAI |
|---|
| root['schemas']['SIEventData']['properties']['rawLogType']['enum'][2968] | WSGC_ECOM |
|---|
| root['schemas']['SearchHistory']['properties']['queryType']['enum'][5] | QUERY_TYPE_DATA_TABLE_QUERY |
|---|
| root['schemas']['SearchHistory']['properties']['queryType']['enumDescriptions'][5] | DataTable Query. |
|---|
| root['schemas']['SearchQuery']['properties']['queryType']['enum'][5] | QUERY_TYPE_DATA_TABLE_QUERY |
|---|
| root['schemas']['SearchQuery']['properties']['queryType']['enumDescriptions'][5] | DataTable Query. |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][1] | Allowed. |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][2] | Blocked. |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][3] | Strip, modify something (e.g. File or email was disinfected or rewritten and still forwarded). |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][4] | Put somewhere for later analysis (does NOT imply block). |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][5] | Failed (e.g. the event was allowed but failed). |
|---|
| root['schemas']['SecurityResult']['properties']['action']['items']['enumDescriptions'][6] | Challenged (e.g. the user was challenged by a Captcha, 2FA). |
|---|
| root['schemas']['SecurityResult']['properties']['alertState']['enumDescriptions'][1] | The security result is not an alert. |
|---|
| root['schemas']['SecurityResult']['properties']['alertState']['enumDescriptions'][2] | The security result is an alert. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][1] | Malware, spyware, rootkit. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][2] | Below the conviction threshold; probably bad. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][3] | Potentially Unwanted App (such as adware). |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][4] | Includes C&C or network exploit. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][5] | Suspicious activity, such as potential reverse tunnel. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][6] | Non-security related: URL has category like gambling or porn. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][7] | DoS, DDoS. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][8] | Port scan detected by an IDS, probing of web app. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][9] | If we know this is a C&C channel. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][10] | Unauthorized access attempted, including attempted access to files, web services, processes, web objects, etc. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][11] | Authentication failed (e.g. bad password or bad 2-factor authentication). |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][12] | Exploit: For all manner of exploits including attempted overflows, bad protocol encodings, ROP, SQL injection, etc. For both network and host- based exploits. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][13] | DLP: Sensitive data transmission, copy to thumb drive. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][14] | DLP: Sensitive data found at rest in a scan. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][15] | Attempt to destroy/delete data. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][16] | TOR Exit Nodes. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][17] | Spam email, message, etc. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][18] | Phishing email, chat messages, etc. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][19] | Spoofed source email address, etc. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][20] | Security-related policy violation (e.g. firewall/proxy/HIPS rule violated, NAC block action). |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][21] | Threats which manipulate to break normal security procedures. |
|---|
| root['schemas']['SecurityResult']['properties']['category']['items']['enumDescriptions'][22] | Phishing pages, pops, https phishing etc. |
|---|
| root['schemas']['SecurityResult']['properties']['confidence']['enumDescriptions'][1] | Low confidence. |
|---|
| root['schemas']['SecurityResult']['properties']['confidence']['enumDescriptions'][2] | Medium confidence. |
|---|
| root['schemas']['SecurityResult']['properties']['confidence']['enumDescriptions'][3] | High confidence. |
|---|
| root['schemas']['SecurityResult']['properties']['priority']['enumDescriptions'][1] | Low priority. |
|---|
| root['schemas']['SecurityResult']['properties']['priority']['enumDescriptions'][2] | Medium priority. |
|---|
| root['schemas']['SecurityResult']['properties']['priority']['enumDescriptions'][3] | High priority. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][1] | Info severity. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][2] | An error. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][3] | No malicious result. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][4] | Low-severity malicious result. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][5] | Medium-severity malicious result. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][6] | High-severity malicious result. |
|---|
| root['schemas']['SecurityResult']['properties']['severity']['enumDescriptions'][7] | Critical-severity malicious result. |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][1] | Ingested Raw telemetry |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][2] | Chronicle Rules engine |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][3] | Uppercase |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][4] | DSML - Machine Intelligence |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][5] | A normalized telemetry event from Google Security Command Center. |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][6] | Unspecified Namespace |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][7] | An alert coming from other SIEMs via Chronicle SOAR. |
|---|
| root['schemas']['SecurityResult']['properties']['threatIdNamespace']['enumDescriptions'][8] | VirusTotal. |
|---|
| root['schemas']['SecurityResult']['properties']['threatStatus']['enumDescriptions'][1] | Active threat. |
|---|
| root['schemas']['SecurityResult']['properties']['threatStatus']['enumDescriptions'][2] | Cleared threat. |
|---|
| root['schemas']['SecurityResult']['properties']['threatStatus']['enumDescriptions'][3] | False positive. |
|---|
| root['schemas']['SecurityResult']['properties']['threatVerdict']['enumDescriptions'][1] | Undetected threat verdict level. |
|---|
| root['schemas']['SecurityResult']['properties']['threatVerdict']['enumDescriptions'][2] | Suspicious threat verdict level. |
|---|
| root['schemas']['SecurityResult']['properties']['threatVerdict']['enumDescriptions'][3] | Malicious threat verdict level. |
|---|
| root['schemas']['Source']['properties']['quality']['enumDescriptions'][1] | Low confidence. |
|---|
| root['schemas']['Source']['properties']['quality']['enumDescriptions'][2] | Medium confidence. |
|---|
| root['schemas']['Source']['properties']['quality']['enumDescriptions'][3] | High confidence. |
|---|
| root['schemas']['User']['properties']['accountType']['enumDescriptions'][1] | A human account part of some domain in directory services. |
|---|
| root['schemas']['User']['properties']['accountType']['enumDescriptions'][2] | A local machine account. |
|---|
| root['schemas']['User']['properties']['accountType']['enumDescriptions'][3] | A SaaS service account type (such as Slack or GitHub). |
|---|
| root['schemas']['User']['properties']['accountType']['enumDescriptions'][4] | A non-human account for data access. |
|---|
| root['schemas']['User']['properties']['accountType']['enumDescriptions'][5] | A system built in default account. |
|---|
| root['schemas']['User']['properties']['userAuthenticationStatus']['enumDescriptions'][1] | The authentication method is in active state. |
|---|
| root['schemas']['User']['properties']['userAuthenticationStatus']['enumDescriptions'][2] | The authentication method is in suspended/disabled state. |
|---|
| root['schemas']['User']['properties']['userAuthenticationStatus']['enumDescriptions'][3] | The authentication method has no active credentials. |
|---|
| root['schemas']['User']['properties']['userAuthenticationStatus']['enumDescriptions'][4] | The authentication method has been deleted. |
|---|
| root['schemas']['User']['properties']['userRole']['enumDescriptions'][1] | Product administrator with elevated privileges. |
|---|
| root['schemas']['User']['properties']['userRole']['enumDescriptions'][2] | System service account for automated privilege access. Deprecated: not a role, instead set User.account_type. |
|---|
| root['schemas']['UserError']['properties']['reason']['enum'][15] | INVALID_CONFIG_FOR_DASHBOARD_IMPORT |
|---|
| root['schemas']['UserError']['properties']['reason']['enum'][16] | RETROHUNT_LIMIT_REACHED |
|---|
| root['schemas']['UserError']['properties']['reason']['enumDescriptions'][15] | Invalid config for dashboard import. Example ErrorInfo: { "reason": "INVALID_CONFIG_FOR_DASHBOARD_IMPORT", "domain": "chronicle.googleapis.com", } |
|---|
| root['schemas']['UserError']['properties']['reason']['enumDescriptions'][16] | The user has reached the limit of retrohunts that can be run. Returns the retrohunt limit as metadata labeled `retrohunt_limit`. Example ErrorInfo: { "reason": "RETROHUNT_LIMIT_REACHED", "domain": "chronicle.googleapis.com", "metadata": { "retrohunt_limit": "10", } } |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][1] | Allowed. |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][2] | Blocked. |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][3] | Strip, modify something (e.g. File or email was disinfected or rewritten and still forwarded). |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][4] | Put somewhere for later analysis (does NOT imply block). |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][5] | Failed (e.g. the event was allowed but failed). |
|---|
| root['schemas']['UserEvent']['properties']['eventOutcome']['enumDescriptions'][6] | Challenged (e.g. the user was challenged by a Captcha, 2FA). |
|---|
| root['schemas']['ValidateQueryResponse']['properties']['queryType']['enum'][5] | QUERY_TYPE_DATA_TABLE_QUERY |
|---|
| root['schemas']['ValidateQueryResponse']['properties']['queryType']['enumDescriptions'][5] | DataTable Query. |
|---|
| root['schemas']['VerdictInfo']['properties']['verdictResponse']['enumDescriptions'][1] | VerdictResponse resulted a threat as malicious. |
|---|
| root['schemas']['VerdictInfo']['properties']['verdictResponse']['enumDescriptions'][2] | VerdictResponse resulted a threat as benign. |
|---|
| root['schemas']['VerdictInfo']['properties']['verdictType']['enumDescriptions'][1] | MLVerdict result provided from threat providers, like Mandiant. These fields are used to model Mandiant sources. |
|---|
| root['schemas']['VerdictInfo']['properties']['verdictType']['enumDescriptions'][2] | Verdict provided by the human analyst. These fields are used to model Mandiant sources. |
|---|
| root['schemas']['Vulnerability']['properties']['severity']['enumDescriptions'][1] | Low severity. |
|---|
| root['schemas']['Vulnerability']['properties']['severity']['enumDescriptions'][2] | Medium severity. |
|---|
| root['schemas']['Vulnerability']['properties']['severity']['enumDescriptions'][3] | High severity. |
|---|
| root['schemas']['Vulnerability']['properties']['severity']['enumDescriptions'][4] | Critical severity. |
|---|