For the complete documentation index, see llms.txt. This page is also available as Markdown.

XDR_DATA Fields

This section lists all of the xdr_data dataset fields in alphabetical order.

Field Name
Data Type
Description

_insert_time

INTEGER

System field: The time the data entry was added to the system.

_product

STRING

System field: The data product as ingested from the data collector.

_raw_json

RECORD

System field: All raw data as ingested from the data collector in a JSON format.

_raw_log

STRING

System field: All raw data as ingested from the data collector in a text format.

_time

INTEGER

System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database.

_vendor

STRING

System field: The data vendor as ingested from the data collector.

action_threat_ids

STRING

Threat IDs

additional_info

STRING

Additional information for any event that occurred (GlobalProtect).

agent_content_version

STRING

The agent content version.

agent_external_ip

STRING

External IP of the agent reporting this event.

agent_host_boot_time

INTEGER

Last time this host was started in epoch time.

agent_hostname

STRING

Hostname of the agent.

agent_id

STRING

A unique identifier per agent.

agent_install_type

INTEGER

Agent installation type with the following possible values: 0 - Standard agent 1 - Virtual Desktop Infrastructure (VDI) instance 2 - Virtual Desktop Infrastructure (VDI) golden image 4 - Temporary session 5 - Light agent

agent_interface_map

RECORD

Agent interface maps (IPs and Mac).

agent_ip_addresses

STRING

All IPv4 interface addresses.

agent_ip_addresses_v6

STRING

All IPv6 interface addresses.

agent_is_vdi

BOOLEAN

Indicates whether or not the agent is a VDI agent.

agent_mac_addresses

RECORD

Mac addresses assigned to all interfaces for this agent.

agent_os_sub_type

STRING

A lengthier description of the operating system (OS) type.

agent_os_type

INTEGER

Windows = 1 MacOS = 2 Linux = 4

agent_request_time

agent_session_start_time

INTEGER

Indicates when the agent was started.

agent_status_component

STRING

Gives the name of the endpoint detection and response (EDR) filter that was updated.

agent_version

STRING

The agent version.

associated_event_ids

STRING

associated_mac

STRING

Associated mac addresses.

association_strength

INTEGER

Indicates whether an agent_id includes an associated value using this enum mapping: 10 IP Address 20 MAC 30 Hardware ID 35 Collector ID 40 Agent ID 45 Collector Event Data 50 Event Data

auth_client

STRING

The client-side host.

auth_client_type

STRING

Type of device that the client operated from, such as a computer.

auth_correlation_id

STRING

Identifies events from seperate sessions that occurred together as part of an operation.

auth_domain

STRING

User-side domain name.

auth_identity

STRING

Client-side identification.

auth_identity_display_name

STRING

Display name of the authentication actor.

auth_identity_id

STRING

Identity \ Principal ID

auth_identity_sid

STRING

Identity SID

auth_is_interactive

BOOLEAN

True: Interactive sign-ins, where a user manually signs in using their username and password. False: Non-interactive sign-ins, such as a service-to-service authentication.

auth_method

STRING

Auth method, such as a publickey and password.

auth_mfa_needed

BOOLEAN

Indicates whether or not a Multi-factor authentication (MFA) is required.

auth_normalized_user

RECORD

Normalized user information.

auth_outcome

STRING

Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE".

auth_outcome_reason

STRING

Event success status description.

auth_server

STRING

Server-side host.

auth_service

STRING

Authentication service name.

auth_service_sid

STRING

Service SID

auth_target

STRING

Authentication target host.

auth_target_id

STRING

Target \ Resource ID

azure_ad_resource_display_name

STRING

Display name of the Azure AD resource (authentication server).

azure_ad_resource_id

STRING

Resource ID

azure_ad_resource_tenant_id

STRING

Resource tenant ID.

azure_authentication_info

azure_authentication_risk_info

backtrace_identities

RECORD

cef_device_product

STRING

Extracted CEF product.

cef_device_vendor

STRING

Extracted CEF vendor.

cef_device_version

STRING

Extracted CEF device version.

cef_extension

STRING

Extracted CEF extension.

cef_severity

STRING

Extracted CEF severity.

cef_signature_id

STRING

Extracted CEF signature ID.

cef_version

INTEGER

Extracted CEF version.

checkpoint_vpn_data

cisco_vpn_data

client_version

INTEGER

The endpoints GlobalProtect version.

client_version_str

clipboard_data_size

INTEGER

Size of data.

clipboard_data_type

INTEGER

CF_UNICODETEXT, CF_BITMAP

clipboard_source_iid

STRING

IID of the source process of the copied data.

cloud_entity

RECORD

Cloud provider information on the source IP of the activity.

customerId

STRING

Extracted customer ID.

device_id

RECORD

device_name

dfe_labels

STRING

Story label

directionality_strength

dns_query_items

RECORD

List of all the request items (name and type).

dns_query_name

STRING

DNS request name.

dns_query_name_domain_randomness

RECORD

Domain randomness score.

dns_query_type

STRING

DNS query type.

dns_reply_code

STRING

0 -> No error 1 -> Format Error 2 -> Server Failure 3 -> Non-Existent Domain 4 -> Not Implemented 5 -> Query Refused 6 -> Name Exists when it should not 7 -> RR Set Exists when it should not 8 -> RR Set that should exist does not 9 -> Server Not Authoritative for zone 10 -> Name not contained in zone 16 -> Bad OPT Version 16 -> TSIG Signature Failure 17 -> Key not recognized 18 -> Signature out of time window 19 -> Bad TKEY Mode 20 -> Duplicate key name 21 -> Algorithm not supported 22 -> Bad Truncation

dns_reply_codes

RECORD

DNS reply codes for the DNS query.

dns_resolutions

RECORD

DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item.

dst_action_as_data

RECORD

ASN data from the destination of the network activity.

dst_action_boot_time

INTEGER

Destination computer boot time in ms since the last epoch time.

dst_action_country

STRING

Destination country of the action.

dst_action_external_hostname

STRING

The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action_remote_ip.

dst_action_external_hostname_domain_randomness

RECORD

Domain randomness score.

dst_action_external_port

INTEGER

The port Cortex XDR/XSIAM connects to. For a proxy connection, this value can differ from the action_remote_port.

dst_action_location

RECORD

Geolocation information of the destination IP.

dst_action_powered_off

BOOLEAN

True, if the computer is powered off, such as suspend or hibernate. False, otherwise.

dst_action_url_category

STRING

Next-Generation Firewall (NGFW) URL category.

dst_action_user_agent

STRING

The user agent used by an actor to perform an action.

dst_action_user_is_local_session

BOOLEAN

Indicates whether or not the user login from a remote computer or locally.

dst_action_user_session_id

INTEGER

Session ID of the action.

dst_action_user_status

INTEGER

Same as the event sub-type.

dst_action_user_status_sid

STRING

Security identifier (SID) of the user.

dst_action_username

STRING

Name of the destination user.

dst_agent_content_version

STRING

Agent content version.

dst_agent_external_ip

STRING

The IP that the destination agent reported this data.

dst_agent_host_boot_time

INTEGER

Host boot time in epoch time.

dst_agent_hostname

STRING

Agent hostname

dst_agent_id

STRING

Agent ID

dst_agent_install_type

INTEGER

Type of agent installation: 0 - Standard agent 1 - VDI instance 2 - VDI golden image 4 - Temporary session 5 - Light agent

dst_agent_interface_map

RECORD

Agent interface maps (IPs and Mac)

dst_agent_ip_addresses

STRING

Agent IPv4 addresses.

dst_agent_ip_addresses_v6

STRING

Agent IPv6 addresses.

dst_agent_is_vdi

BOOLEAN

Indicates whether or not the agent is a VDI installation.

dst_agent_os_sub_type

STRING

A lengthier description of the Operating System (OS) type.

dst_agent_os_type

INTEGER

Agent Operating System types: Windows = 1 MacOS = 2 Linux = 4

dst_agent_request_time

dst_agent_session_start_time

INTEGER

When the agent was started.

dst_agent_status_component

STRING

dst_agent_version

STRING

Agent version

dst_associated_mac

STRING

Associated MAC address.

dst_association_strength

INTEGER

Specifies whether an agent_id includes an associated value, using this enum mapping: 0 = No association 10 = IP Address 15 = Kerberos 20 = MAC 30 = Hardware ID 35 = Collector ID 40 = Agent ID 45 = Collector Event Data 50 = Event Data

dst_causality_actor_primary_normalized_user

RECORD

A normalized user for the causality chain.

dst_cloud_entity

RECORD

Cloud provider information on the destination IP of the activity.

dst_device_id

dst_event_utc_diff_minutes

INTEGER

The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone.

dst_host_metadata_domain

STRING

Domain of the host.

dst_host_metadata_hostname

STRING

Hostname

dst_host_metadata_interface_map

RECORD

Agent interface maps (IPs and Mac)

dst_is_internal_ip

BOOLEAN

Indicates whether or not the source IP is outside the private range.

dst_mac

STRING

MAC address

dst_manifest_file_version

INTEGER

dst_tcp_flags

INTEGER

TCP flags

dst_trapsId

STRING

DEPRECATED

dst_ttl

INTEGER

The closest time-to-live (TTL) preceding / following the sensor.

dst_user_id

STRING

Windows: Primary user token of the executed binary. Unix: Effective UID of the executed binary.

dst_xdr_pro_lite

BOOLEAN

Indicates whether or not the destination agent is running XDR Pro (not XTH).

dynamic_event_int_map

RECORD

DEPRECATED

dynamic_event_string_map

RECORD

Same as dynamic_event_int_map, only those are string values.

event_address_code_symbol

STRING

event_address_mapped_image_path

STRING

Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in.

event_allocation_base_shellcode_buffer

STRING

Hexlified buffer of shellcode at the base of the allocation of the event associated buffer.

event_call_region_base_address

INTEGER

Call region base address related to the event.

event_call_region_shellcode_buffer

STRING

Hexlified buffer of shellcode at the call region.

event_causality_mark_of_cain

INTEGER

Indicates whether a security event, such as BTP and static analysis, was raised in this causality. kNotification (1) - A security event has occurred and has NOT been prevented. kPrevention (2) - A security event has occurred but was (partially or fully) prevented.

event_direct_syscall_ip_mapped_file_path

STRING

When the event is a direct syscall, this field contains the DLL that the syscall originated from.

event_id

STRING

Event identifier

event_impersonation_status

INTEGER

This is equivalent to the event_is_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 Impersonated = 1 Not-Impersonated = 2

event_invalidity_field

STRING

Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid.

event_is_boot_replay

BOOLEAN

A boolean value that is true during the the first replay.

event_is_duplicated_replay

BOOLEAN

A boolean value that is true if the event was already sent before and another replay sends this event again.

event_is_impersonated

BOOLEAN

Windows: Indicates whether or not the thread performing the event is impersonating.

event_is_replay

BOOLEAN

Indicates whether or not the event is part of the system state replay sent when the agent is started.

event_is_simulated

BOOLEAN

Indicates whether or not this event was simulated by the TMS.

event_page_base_shellcode_buffer

STRING

Hexlified buffer of shellcode at the base of the page of the event associated buffer.

event_resolved_stack_trace

STRING

Stack trace related to the event.

event_rpc_func_opnum

INTEGER

Integer identifying the function being called.

event_rpc_interface_uuid

STRING

UUID identifying the interface.

event_rpc_interface_version_major

INTEGER

Major version of the remote procedure call (RPC) interface.

event_rpc_interface_version_minor

INTEGER

minor version of the remote procedure call (RPC) interface.

event_rpc_protocol

INTEGER

Enum representing the remote procedure call (RPC) protocol: LocalRpc (ALPC port) = 0 Tcp = 1 NamedPipes = 2 Http = 3

event_shellcode_address

INTEGER

The address of the shellcode in the usermode callstack.

event_source_bitmask

INTEGER

Bitmask of the sources involved in producing the event: Simulated - 0x01 Kernel-Module - 0x02 EBPF - 0x04 Fanotify - 0x08 Path-Resolved - 0x10

event_sub_type

INTEGER

This field is updated based on the event type defined in the event_type field. For each event type, there are multiple event sub types. To see the possible values for the event_type and event_sub_type, create an XQL query with a filter stage, which autocompletes the values.

event_thread_context

STRING

A string representing a JSON array containing thread specific context. Note: From XDR agent 8.2, this field is only relevant for office macros.

event_timestamp

INTEGER

Integer indicating when the event occurred.

event_timestamp_original

INTEGER

Event timestamp in epoch time.

event_type

INTEGER

A unique identifier of the event type: Process = 1 Network = 2 File = 3 Registry = 4 Injection = 5 LoadImage = 6 UserStatusChange = 7 TimeChange = 8 Thread = 9 Causality = 10 HostStatusChange = 11 AgentStatusChange = 12 InternalStatistics = 13 ProcessHandle = 14 WindowsEventLog = 15 EpmStatus = 16 MetadataChange = 17 SystemCall = 18 Device = 19 HostFirewall = 23

event_user_presence

BOOLEAN

Indicates whether or not there was a physical user presence on the machine. Windows: The value is"true" if the user session was unlocked during the event.

event_user_presence_status

INTEGER

This is equivalent to the event_user_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 User not present = 1 User present = 2

event_user_thread_context_ip

INTEGER

The instruction pointer at the moment the syscall was made.

event_user_thread_context_ip_in_native_ntdll

BOOLEAN

Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll.

event_user_thread_context_is_heavens_gate

BOOLEAN

Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process.

event_user_thread_context_is_stack_pivot

BOOLEAN

Indicates whether or not the RSP in the trapframe was not inside the thread stack limits.

event_user_thread_context_sp

INTEGER

The stack pointer at the moment the syscall was made.

event_utc_diff_minutes

INTEGER

The difference in minutes of the original timestamp from UTC.

event_validity_enum

INTEGER

An enum set by the preprocessor when detecting that an event is invalid: 1 - valid 2 - invalid due to future timestamp field. 3 - invalid due to an "old" timestamp field that exceeds the host's boot time.

event_version

INTEGER

Version of the event structure, where each change increases the version.

event_versions

INTEGER

Event version for this event.

execution_actor_causality_id

STRING

Causality ID of the parent which executed the terminated process instance.

execution_actor_instance_id

STRING

Instance ID of the parent which executed the terminated process instance.

facility

STRING

file_data

fw_dst_normalized_user

RECORD

Normalized user information.

fw_identities

RECORD

DEPRECATED

fw_is_dup_log

INTEGER

fw_log_subtypes

STRING

fw_log_types

STRING

fw_src_normalized_user

RECORD

Normalized user information.

fw_time_generated

INTEGER

Equivalent to the event_timestamp.

fw_traffic_flags

INTEGER

Protocol traffic flags as seen on the Next-Generation Firewall (NGFW).

generatedTime

TIMESTAMP

Equivalent to the event_timestamp.

global_protect_data

hardware_id

STRING

Unique identifier GlobalProtect assigned to the host.

host_metadata_domain

STRING

Domain of the host.

host_metadata_hostname

STRING

Hostname

host_metadata_interface_map

RECORD

Agent interface maps (IPs and Mac).

http_content_type

STRING

Content-type header of the HTTP traffic.

http_data

RECORD

HTTP log data.

http_data_is_trimmed

BOOLEAN

Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW).

http_method

STRING

0 = UNKNOWN_METHOD 1 = GET 2 = POST 3 = CONNECT 4 = HEAD 5 = PUT 6 = DELETE 7 = OPTIONS

http_referer

STRING

HTTP Referer header.

http_req_before_method

STRING

http_req_content_type_header

STRING

HTTP content type header.

http_req_host_header

STRING

HTTP host header.

http_req_referer_header

STRING

HTTP Referer header.

http_req_uri

STRING

HTTP request URI.

http_req_user_agent_header

STRING

HTTP user agent header.

http_rsp_code

INTEGER

HTTP response code.

http_rsp_content_type_header

STRING

HTTP response content type header.

http_rsp_filename

STRING

HTTP response filename.

http_server

STRING

HTTP server

http_status_code

INTEGER

HTTP status code.

hwnd

INTEGER

The foreground window.

icmp_code

INTEGER

ICMP protocol request code.

icmp_original_length

INTEGER

Internet Control Message Protocol (ICMP) payload length.

icmp_type

INTEGER

ICMP protocol request type.

insert_timestamp

TIMESTAMP

Ingestion timestamp

is_disintegrated

BOOLEAN

Indicates whether or not the story was disintegrated.

is_internal_ip

BOOLEAN

Indicates whether or not the source IP is outside the private range.

krb_tgs_data

RECORD

Kerberos Ticket Granting Service (TGS) log data.

krb_tgt_data

RECORD

Kerberos Ticket Granting Service (TGS) log data.

ldap_data

RECORD

LDAP log data.

login_data

RECORD

Windows Event Log login data.

login_data_dst_normalized_user

RECORD

Destination user CIE resolution information.

login_data_dst_outbound_normalized_user

RECORD

Destination outbound user DSS resolution information.

login_data_src_normalized_user

RECORD

Source user CIE resolution information.

non_standard_dport

INTEGER

This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic

ntlm_auth_data

RECORD

NTLM log data.

one_login_data

other_json

DEPRECATED

packet

STRING

Packet payload excluding TCP/IP header. Only valid for event_sub_type = 17 (raw_data)

related_alerts

serverTime

TIMESTAMP

Timestamp of the event displayed on the server side.

ssl_data

RECORD

SSL log data.

ssl_req_chello_sni_sample

STRING

SNI domain obtained from SSL protocol parsing.

sso_debug_data

STRING

Okta debug info, which includes protocol informaiton, URIs, and more.

sso_display_message

STRING

Single Sign-on (SSO) event description.

sso_event_type

INTEGER

Single Sign-On (SSO) event type as obtained by the original SSO provider.

sso_severity

STRING

Severity as reported: DEBUG, INFO, WARN, ERROR

story_id

STRING

ID of the story.

story_id_original

DEPRECATED

story_publish_timestamp

INTEGER

Story publishing timestamp in epoch time.

story_version

FLOAT

Story version

syscall_action_etw_based

BOOLEAN

Indicates whether or not the syscall collected is from Windows ETW.

syscall_action_int_params

STRING

Integer parameters from syscalls in a JSON format.

syscall_action_stack_ptr

STRING

syscall_action_string_params

STRING

String parameters from syscalls in a JSON format.

tcp_flags

INTEGER

TCP Flags

title

STRING

Title of top_level_hwnd.

top_level_hwnd

INTEGER

The top level window of the foreground window.

trapsId

STRING

DEPRECATED

ttl

INTEGER

IP Protocol time-to-live (TTL) obtained from the source.

tunnel_type

STRING

The type of tunnel.

uri

STRING

Threat URI

user_generic_value1

INTEGER

A bitmap that can be set in the YAML. The first bit indicates whether an operation is in the GUI or not.

user_generic_value2

INTEGER

An integer that can be set in the YAML. It is used to indicate Yara rule IDs for windows web shells.

user_id

STRING

Windows: User SID Unix: UID

uuid

STRING

Equivalent to the 'event_id'.

vendor

STRING

Log vendor

vpn_event_description

STRING

The name of the GlobalProtect event.

vpn_server

STRING

VPN server name or IP.

vpn_service

STRING

VPN service name.

xdr_pro_lite

BOOLEAN

Indicates whether or not the agent is XDRProNG and sends fewer events.

zip_id

STRING

DEPRECATED

zscaler_vpn_data

Last updated

Was this helpful?