> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields.md).

# XDR\_DATA Fields

This section lists all of the xdr\_data dataset fields in alphabetical order.

| Field Name                                          | Data Type  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| --------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| \_insert\_time                                      | INTEGER    | System field: The time the data entry was added to the system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| \_product                                           | STRING     | System field: The data product as ingested from the data collector.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| \_raw\_json                                         | RECORD     | System field: All raw data as ingested from the data collector in a JSON format.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| \_raw\_log                                          | STRING     | System field: All raw data as ingested from the data collector in a text format.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| \_time                                              | INTEGER    | System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| \_vendor                                            | STRING     | System field: The data vendor as ingested from the data collector.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| action\_threat\_ids                                 | STRING     | Threat IDs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| additional\_info                                    | STRING     | Additional information for any event that occurred (GlobalProtect).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| agent\_content\_version                             | STRING     | The agent content version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| agent\_external\_ip                                 | STRING     | External IP of the agent reporting this event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| agent\_host\_boot\_time                             | INTEGER    | Last time this host was started in epoch time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| agent\_hostname                                     | STRING     | Hostname of the agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| agent\_id                                           | STRING     | A unique identifier per agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| agent\_install\_type                                | INTEGER    | <p>Agent installation type with the following possible values:<br>0 - Standard agent<br>1 - Virtual Desktop Infrastructure (VDI) instance<br>2 - Virtual Desktop Infrastructure (VDI) golden image<br>4 - Temporary session<br>5 - Light agent</p>                                                                                                                                                                                                                                                                                                                                        |
| agent\_interface\_map                               | RECORD     | Agent interface maps (IPs and Mac).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| agent\_ip\_addresses                                | STRING     | All IPv4 interface addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| agent\_ip\_addresses\_v6                            | STRING     | All IPv6 interface addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| agent\_is\_vdi                                      | BOOLEAN    | Indicates whether or not the agent is a VDI agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| agent\_mac\_addresses                               | RECORD     | Mac addresses assigned to all interfaces for this agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| agent\_os\_sub\_type                                | STRING     | A lengthier description of the operating system (OS) type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| agent\_os\_type                                     | INTEGER    | <p>Windows = 1<br>MacOS = 2<br>Linux = 4</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| agent\_request\_time                                |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| agent\_session\_start\_time                         | INTEGER    | Indicates when the agent was started.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| agent\_status\_component                            | STRING     | Gives the name of the endpoint detection and response (EDR) filter that was updated.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| agent\_version                                      | STRING     | The agent version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| associated\_event\_ids                              | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| associated\_mac                                     | STRING     | Associated mac addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| association\_strength                               | INTEGER    | <p>Indicates whether an agent\_id includes an associated value using this enum mapping:<br>10 IP Address<br>20 MAC<br>30 Hardware ID<br>35 Collector ID<br>40 Agent ID<br>45 Collector Event Data<br>50 Event Data</p>                                                                                                                                                                                                                                                                                                                                                                    |
| auth\_client                                        | STRING     | The client-side host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| auth\_client\_type                                  | STRING     | Type of device that the client operated from, such as a computer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| auth\_correlation\_id                               | STRING     | Identifies events from seperate sessions that occurred together as part of an operation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| auth\_domain                                        | STRING     | User-side domain name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| auth\_identity                                      | STRING     | Client-side identification.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| auth\_identity\_display\_name                       | STRING     | Display name of the authentication actor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| auth\_identity\_id                                  | STRING     | Identity \ Principal ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| auth\_identity\_sid                                 | STRING     | Identity SID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| auth\_is\_interactive                               | BOOLEAN    | <p>True: Interactive sign-ins, where a user manually signs in using their username and password.<br>False: Non-interactive sign-ins, such as a service-to-service authentication.</p>                                                                                                                                                                                                                                                                                                                                                                                                     |
| auth\_method                                        | STRING     | Auth method, such as a publickey and password.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| auth\_mfa\_needed                                   | BOOLEAN    | Indicates whether or not a Multi-factor authentication (MFA) is required.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| auth\_normalized\_user                              | RECORD     | Normalized user information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| auth\_outcome                                       | STRING     | Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE".                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| auth\_outcome\_reason                               | STRING     | Event success status description.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| auth\_server                                        | STRING     | Server-side host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| auth\_service                                       | STRING     | Authentication service name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| auth\_service\_sid                                  | STRING     | Service SID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| auth\_target                                        | STRING     | Authentication target host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| auth\_target\_id                                    | STRING     | Target \ Resource ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| azure\_ad\_resource\_display\_name                  | STRING     | Display name of the Azure AD resource (authentication server).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| azure\_ad\_resource\_id                             | STRING     | Resource ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| azure\_ad\_resource\_tenant\_id                     | STRING     | Resource tenant ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| azure\_authentication\_info                         |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| azure\_authentication\_risk\_info                   |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| backtrace\_identities                               | RECORD     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cef\_device\_product                                | STRING     | Extracted CEF product.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cef\_device\_vendor                                 | STRING     | Extracted CEF vendor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cef\_device\_version                                | STRING     | Extracted CEF device version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cef\_extension                                      | STRING     | Extracted CEF extension.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cef\_severity                                       | STRING     | Extracted CEF severity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cef\_signature\_id                                  | STRING     | Extracted CEF signature ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cef\_version                                        | INTEGER    | Extracted CEF version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| checkpoint\_vpn\_data                               |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cisco\_vpn\_data                                    |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| client\_version                                     | INTEGER    | The endpoints GlobalProtect version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| client\_version\_str                                |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| clipboard\_data\_size                               | INTEGER    | Size of data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| clipboard\_data\_type                               | INTEGER    | CF\_UNICODETEXT, CF\_BITMAP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| clipboard\_source\_iid                              | STRING     | IID of the source process of the copied data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cloud\_entity                                       | RECORD     | Cloud provider information on the source IP of the activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| customerId                                          | STRING     | Extracted customer ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| device\_id                                          | RECORD     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| device\_name                                        |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dfe\_labels                                         | STRING     | Story label                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| directionality\_strength                            |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dns\_query\_items                                   | RECORD     | List of all the request items (name and type).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| dns\_query\_name                                    | STRING     | DNS request name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dns\_query\_name\_domain\_randomness                | RECORD     | Domain randomness score.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| dns\_query\_type                                    | STRING     | DNS query type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dns\_reply\_code                                    | STRING     | <p>0 -> No error<br>1 -> Format Error<br>2 -> Server Failure<br>3 -> Non-Existent Domain<br>4 -> Not Implemented<br>5 -> Query Refused<br>6 -> Name Exists when it should not<br>7 -> RR Set Exists when it should not<br>8 -> RR Set that should exist does not<br>9 -> Server Not Authoritative for zone<br>10 -> Name not contained in zone<br>16 -> Bad OPT Version<br>16 -> TSIG Signature Failure<br>17 -> Key not recognized<br>18 -> Signature out of time window<br>19 -> Bad TKEY Mode<br>20 -> Duplicate key name<br>21 -> Algorithm not supported<br>22 -> Bad Truncation</p> |
| dns\_reply\_codes                                   | RECORD     | DNS reply codes for the DNS query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| dns\_resolutions                                    | RECORD     | DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dst\_action\_as\_data                               | RECORD     | ASN data from the destination of the network activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dst\_action\_boot\_time                             | INTEGER    | Destination computer boot time in ms since the last epoch time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_action\_country                                | STRING     | Destination country of the action.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| dst\_action\_external\_hostname                     | STRING     | The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action\_remote\_ip.                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dst\_action\_external\_hostname\_domain\_randomness | RECORD     | Domain randomness score.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| dst\_action\_external\_port                         | INTEGER    | <p>The port Cortex XDR/XSIAM connects to.<br>For a proxy connection, this value can differ from the action\_remote\_port.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_action\_location                               | RECORD     | Geolocation information of the destination IP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| dst\_action\_powered\_off                           | BOOLEAN    | <p>True, if the computer is powered off, such as suspend or hibernate.<br>False, otherwise.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_action\_url\_category                          | STRING     | Next-Generation Firewall (NGFW) URL category.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_action\_user\_agent                            | STRING     | The user agent used by an actor to perform an action.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dst\_action\_user\_is\_local\_session               | BOOLEAN    | Indicates whether or not the user login from a remote computer or locally.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dst\_action\_user\_session\_id                      | INTEGER    | Session ID of the action.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dst\_action\_user\_status                           | INTEGER    | Same as the event sub-type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dst\_action\_user\_status\_sid                      | STRING     | Security identifier (SID) of the user.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dst\_action\_username                               | STRING     | Name of the destination user.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_agent\_content\_version                        | STRING     | Agent content version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dst\_agent\_external\_ip                            | STRING     | The IP that the destination agent reported this data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dst\_agent\_host\_boot\_time                        | INTEGER    | Host boot time in epoch time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_agent\_hostname                                | STRING     | Agent hostname                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| dst\_agent\_id                                      | STRING     | Agent ID                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| dst\_agent\_install\_type                           | INTEGER    | <p>Type of agent installation: 0 - Standard agent<br>1 - VDI instance<br>2 - VDI golden image<br>4 - Temporary session<br>5 - Light agent</p>                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_agent\_interface\_map                          | RECORD     | Agent interface maps (IPs and Mac)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| dst\_agent\_ip\_addresses                           | STRING     | Agent IPv4 addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dst\_agent\_ip\_addresses\_v6                       | STRING     | Agent IPv6 addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dst\_agent\_is\_vdi                                 | BOOLEAN    | Indicates whether or not the agent is a VDI installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dst\_agent\_os\_sub\_type                           | STRING     | A lengthier description of the Operating System (OS) type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dst\_agent\_os\_type                                | INTEGER    | <p>Agent Operating System types: Windows = 1<br>MacOS = 2<br>Linux = 4</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dst\_agent\_request\_time                           |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_agent\_session\_start\_time                    | INTEGER    | When the agent was started.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dst\_agent\_status\_component                       | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_agent\_version                                 | STRING     | Agent version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dst\_associated\_mac                                | STRING     | Associated MAC address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| dst\_association\_strength                          | INTEGER    | <p>Specifies whether an agent\_id includes an associated value, using this enum mapping:<br>0 = No association<br>10 = IP Address<br>15 = Kerberos<br>20 = MAC<br>30 = Hardware ID<br>35 = Collector ID<br>40 = Agent ID<br>45 = Collector Event Data<br>50 = Event Data</p>                                                                                                                                                                                                                                                                                                              |
| dst\_causality\_actor\_primary\_normalized\_user    | RECORD     | A normalized user for the causality chain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dst\_cloud\_entity                                  | RECORD     | Cloud provider information on the destination IP of the activity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dst\_device\_id                                     |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_event\_utc\_diff\_minutes                      | INTEGER    | The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| dst\_host\_metadata\_domain                         | STRING     | Domain of the host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dst\_host\_metadata\_hostname                       | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Hostname                                            |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_host\_metadata\_interface\_map                 | RECORD     | Agent interface maps (IPs and Mac)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| dst\_is\_internal\_ip                               | BOOLEAN    | Indicates whether or not the source IP is outside the private range.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dst\_mac                                            | STRING     | MAC address                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dst\_manifest\_file\_version                        | INTEGER    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dst\_tcp\_flags                                     | INTEGER    | TCP flags                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dst\_trapsId                                        | STRING     | DEPRECATED                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dst\_ttl                                            | INTEGER    | The closest time-to-live (TTL) preceding / following the sensor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| dst\_user\_id                                       | STRING     | <p>Windows: Primary user token of the executed binary.<br>Unix: Effective UID of the executed binary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dst\_xdr\_pro\_lite                                 | BOOLEAN    | Indicates whether or not the destination agent is running XDR Pro (not XTH).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| dynamic\_event\_int\_map                            | RECORD     | DEPRECATED                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dynamic\_event\_string\_map                         | RECORD     | Same as dynamic\_event\_int\_map, only those are string values.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| event\_address\_code\_symbol                        | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| event\_address\_mapped\_image\_path                 | STRING     | Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in.                                                                                                                                                                                                                                                                                                                                                                                                            |
| event\_allocation\_base\_shellcode\_buffer          | STRING     | Hexlified buffer of shellcode at the base of the allocation of the event associated buffer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| event\_call\_region\_base\_address                  | INTEGER    | Call region base address related to the event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| event\_call\_region\_shellcode\_buffer              | STRING     | Hexlified buffer of shellcode at the call region.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| event\_causality\_mark\_of\_cain                    | INTEGER    | <p>Indicates whether a security event, such as BTP and static analysis, was raised in this causality.<br>kNotification (1) - A security event has occurred and has NOT been prevented.<br>kPrevention (2) - A security event has occurred but was (partially or fully) prevented.</p>                                                                                                                                                                                                                                                                                                     |
| event\_direct\_syscall\_ip\_mapped\_file\_path      | STRING     | When the event is a direct syscall, this field contains the DLL that the syscall originated from.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| event\_id                                           | STRING     | Event identifier                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| event\_impersonation\_status                        | INTEGER    | <p>This is equivalent to the event\_is\_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.<br>Unknown = 0<br>Impersonated = 1<br>Not-Impersonated = 2</p>                                                                                                                                                                                                                                                                                                                                                           |
| event\_invalidity\_field                            | STRING     | Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid.                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| event\_is\_boot\_replay                             | BOOLEAN    | A boolean value that is true during the the first replay.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| event\_is\_duplicated\_replay                       | BOOLEAN    | A boolean value that is true if the event was already sent before and another replay sends this event again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| event\_is\_impersonated                             | BOOLEAN    | Windows: Indicates whether or not the thread performing the event is impersonating.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| event\_is\_replay                                   | BOOLEAN    | Indicates whether or not the event is part of the system state replay sent when the agent is started.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| event\_is\_simulated                                | BOOLEAN    | Indicates whether or not this event was simulated by the TMS.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| event\_page\_base\_shellcode\_buffer                | STRING     | Hexlified buffer of shellcode at the base of the page of the event associated buffer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| event\_resolved\_stack\_trace                       | STRING     | Stack trace related to the event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| event\_rpc\_func\_opnum                             | INTEGER    | Integer identifying the function being called.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| event\_rpc\_interface\_uuid                         | STRING     | UUID identifying the interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| event\_rpc\_interface\_version\_major               | INTEGER    | Major version of the remote procedure call (RPC) interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| event\_rpc\_interface\_version\_minor               | INTEGER    | minor version of the remote procedure call (RPC) interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| event\_rpc\_protocol                                | INTEGER    | <p>Enum representing the remote procedure call (RPC) protocol:<br>LocalRpc (ALPC port) = 0<br>Tcp = 1<br>NamedPipes = 2<br>Http = 3</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| event\_shellcode\_address                           | INTEGER    | The address of the shellcode in the usermode callstack.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| event\_source\_bitmask                              | INTEGER    | <p>Bitmask of the sources involved in producing the event:<br>Simulated - 0x01<br>Kernel-Module - 0x02<br>EBPF - 0x04<br>Fanotify - 0x08<br>Path-Resolved - 0x10</p>                                                                                                                                                                                                                                                                                                                                                                                                                      |
| event\_sub\_type                                    | INTEGER    | <p>This field is updated based on the event type defined in the event\_type field. For each event type, there are multiple event sub types.<br>To see the possible values for the event\_type and event\_sub\_type, create an XQL query with a filter stage, which autocompletes the values.</p>                                                                                                                                                                                                                                                                                          |
| event\_thread\_context                              | STRING     | <p>A string representing a JSON array containing thread specific context.<br>Note: From XDR agent 8.2, this field is only relevant for office macros.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| event\_timestamp                                    | INTEGER    | Integer indicating when the event occurred.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| event\_timestamp\_original                          | INTEGER    | Event timestamp in epoch time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| event\_type                                         | INTEGER    | <p>A unique identifier of the event type:<br>Process = 1<br>Network = 2<br>File = 3<br>Registry = 4<br>Injection = 5<br>LoadImage = 6<br>UserStatusChange = 7<br>TimeChange = 8<br>Thread = 9<br>Causality = 10<br>HostStatusChange = 11<br>AgentStatusChange = 12<br>InternalStatistics = 13<br>ProcessHandle = 14<br>WindowsEventLog = 15<br>EpmStatus = 16<br>MetadataChange = 17<br>SystemCall = 18<br>Device = 19<br>HostFirewall = 23</p>                                                                                                                                           |
| event\_user\_presence                               | BOOLEAN    | <p>Indicates whether or not there was a physical user presence on the machine.<br>Windows: The value is"true" if the user session was unlocked during the event.</p>                                                                                                                                                                                                                                                                                                                                                                                                                      |
| event\_user\_presence\_status                       | INTEGER    | <p>This is equivalent to the event\_user\_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field.<br>Unknown = 0<br>User not present = 1<br>User present = 2</p>                                                                                                                                                                                                                                                                                                                                                             |
| event\_user\_thread\_context\_ip                    | INTEGER    | The instruction pointer at the moment the syscall was made.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| event\_user\_thread\_context\_ip\_in\_native\_ntdll | BOOLEAN    | Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| event\_user\_thread\_context\_is\_heavens\_gate     | BOOLEAN    | Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process.                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| event\_user\_thread\_context\_is\_stack\_pivot      | BOOLEAN    | Indicates whether or not the RSP in the trapframe was not inside the thread stack limits.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| event\_user\_thread\_context\_sp                    | INTEGER    | The stack pointer at the moment the syscall was made.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| event\_utc\_diff\_minutes                           | INTEGER    | The difference in minutes of the original timestamp from UTC.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| event\_validity\_enum                               | INTEGER    | <p>An enum set by the preprocessor when detecting that an event is invalid:<br>1 - valid<br>2 - invalid due to future timestamp field.<br>3 - invalid due to an "old" timestamp field that exceeds the host's boot time.</p>                                                                                                                                                                                                                                                                                                                                                              |
| event\_version                                      | INTEGER    | Version of the event structure, where each change increases the version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| event\_versions                                     | INTEGER    | Event version for this event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| execution\_actor\_causality\_id                     | STRING     | Causality ID of the parent which executed the terminated process instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| execution\_actor\_instance\_id                      | STRING     | Instance ID of the parent which executed the terminated process instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| facility                                            | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| file\_data                                          |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fw\_dst\_normalized\_user                           | RECORD     | Normalized user information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| fw\_identities                                      | RECORD     | DEPRECATED                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| fw\_is\_dup\_log                                    | INTEGER    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fw\_log\_subtypes                                   | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fw\_log\_types                                      | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fw\_src\_normalized\_user                           | RECORD     | Normalized user information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| fw\_time\_generated                                 | INTEGER    | Equivalent to the event\_timestamp.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| fw\_traffic\_flags                                  | INTEGER    | Protocol traffic flags as seen on the Next-Generation Firewall (NGFW).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| generatedTime                                       | TIMESTAMP  | Equivalent to the event\_timestamp.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| global\_protect\_data                               |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| hardware\_id                                        | STRING     | Unique identifier GlobalProtect assigned to the host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| host\_metadata\_domain                              | STRING     | Domain of the host.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| host\_metadata\_hostname                            | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Hostname                                            |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| host\_metadata\_interface\_map                      | RECORD     | Agent interface maps (IPs and Mac).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| http\_content\_type                                 | STRING     | Content-type header of the HTTP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| http\_data                                          | RECORD     | HTTP log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| http\_data\_is\_trimmed                             | BOOLEAN    | Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| http\_method                                        | STRING     | <p>0 = UNKNOWN\_METHOD<br>1 = GET<br>2 = POST<br>3 = CONNECT<br>4 = HEAD<br>5 = PUT<br>6 = DELETE<br>7 = OPTIONS</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| http\_referer                                       | STRING     | HTTP Referer header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| http\_req\_before\_method                           | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| http\_req\_content\_type\_header                    | STRING     | HTTP content type header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| http\_req\_host\_header                             | STRING     | HTTP host header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| http\_req\_referer\_header                          | STRING     | HTTP Referer header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| http\_req\_uri                                      | STRING     | HTTP request URI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| http\_req\_user\_agent\_header                      | STRING     | HTTP user agent header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| http\_rsp\_code                                     | INTEGER    | HTTP response code.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| http\_rsp\_content\_type\_header                    | STRING     | HTTP response content type header.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| http\_rsp\_filename                                 | STRING     | HTTP response filename.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| http\_server                                        | STRING     | HTTP server                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| http\_status\_code                                  | INTEGER    | HTTP status code.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| hwnd                                                | INTEGER    | The foreground window.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| icmp\_code                                          | INTEGER    | ICMP protocol request code.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| icmp\_original\_length                              | INTEGER    | Internet Control Message Protocol (ICMP) payload length.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| icmp\_type                                          | INTEGER    | ICMP protocol request type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| insert\_timestamp                                   | TIMESTAMP  | Ingestion timestamp                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| is\_disintegrated                                   | BOOLEAN    | Indicates whether or not the story was disintegrated.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| is\_internal\_ip                                    | BOOLEAN    | Indicates whether or not the source IP is outside the private range.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| krb\_tgs\_data                                      | RECORD     | Kerberos Ticket Granting Service (TGS) log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| krb\_tgt\_data                                      | RECORD     | Kerberos Ticket Granting Service (TGS) log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ldap\_data                                          | RECORD     | LDAP log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| login\_data                                         | RECORD     | Windows Event Log login data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| login\_data\_dst\_normalized\_user                  | RECORD     | Destination user CIE resolution information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| login\_data\_dst\_outbound\_normalized\_user        | RECORD     | Destination outbound user DSS resolution information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| login\_data\_src\_normalized\_user                  | RECORD     | Source user CIE resolution information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| non\_standard\_dport                                | INTEGER    | This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ntlm\_auth\_data                                    | RECORD     | NTLM log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| one\_login\_data                                    |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| other\_json                                         | DEPRECATED |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| packet                                              | STRING     | <p>Packet payload excluding TCP/IP header.<br>Only valid for event\_sub\_type = 17 (raw\_data)</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| related\_alerts                                     |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| serverTime                                          | TIMESTAMP  | Timestamp of the event displayed on the server side.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ssl\_data                                           | RECORD     | SSL log data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ssl\_req\_chello\_sni\_sample                       | STRING     | SNI domain obtained from SSL protocol parsing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| sso\_debug\_data                                    | STRING     | Okta debug info, which includes protocol informaiton, URIs, and more.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| sso\_display\_message                               | STRING     | Single Sign-on (SSO) event description.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| sso\_event\_type                                    | INTEGER    | Single Sign-On (SSO) event type as obtained by the original SSO provider.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| sso\_severity                                       | STRING     | Severity as reported: DEBUG, INFO, WARN, ERROR                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| story\_id                                           | STRING     | ID of the story.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| story\_id\_original                                 | DEPRECATED |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| story\_publish\_timestamp                           | INTEGER    | Story publishing timestamp in epoch time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| story\_version                                      | FLOAT      | Story version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| syscall\_action\_etw\_based                         | BOOLEAN    | Indicates whether or not the syscall collected is from Windows ETW.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| syscall\_action\_int\_params                        | STRING     | Integer parameters from syscalls in a JSON format.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| syscall\_action\_stack\_ptr                         | STRING     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| syscall\_action\_string\_params                     | STRING     | String parameters from syscalls in a JSON format.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| tcp\_flags                                          | INTEGER    | TCP Flags                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| title                                               | STRING     | Title of top\_level\_hwnd.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| top\_level\_hwnd                                    | INTEGER    | The top level window of the foreground window.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| trapsId                                             | STRING     | DEPRECATED                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ttl                                                 | INTEGER    | IP Protocol time-to-live (TTL) obtained from the source.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| tunnel\_type                                        | STRING     | The type of tunnel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| uri                                                 | STRING     | Threat URI                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| user\_generic\_value1                               | INTEGER    | <p>A bitmap that can be set in the YAML.<br>The first bit indicates whether an operation is in the GUI or not.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| user\_generic\_value2                               | INTEGER    | <p>An integer that can be set in the YAML.<br>It is used to indicate Yara rule IDs for windows web shells.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| user\_id                                            | STRING     | <p>Windows: User SID<br>Unix: UID</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| uuid                                                | STRING     | Equivalent to the 'event\_id'.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| vendor                                              | STRING     | Log vendor                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| vpn\_event\_description                             | STRING     | The name of the GlobalProtect event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| vpn\_server                                         | STRING     | VPN server name or IP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| vpn\_service                                        | STRING     | VPN service name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| xdr\_pro\_lite                                      | BOOLEAN    | Indicates whether or not the agent is XDRProNG and sends fewer events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| zip\_id                                             | STRING     | DEPRECATED                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| zscaler\_vpn\_data                                  |            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xql-schema-reference/xdr-data-fields.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
