XDR_DATA Fields
This section lists all of the xdr_data dataset fields in alphabetical order.
_insert_time
INTEGER
System field: The time the data entry was added to the system.
_product
STRING
System field: The data product as ingested from the data collector.
_raw_json
RECORD
System field: All raw data as ingested from the data collector in a JSON format.
_raw_log
STRING
System field: All raw data as ingested from the data collector in a text format.
_time
INTEGER
System field: Data entry's timestamp. If unknown, then the time the data entry was added to the database.
_vendor
STRING
System field: The data vendor as ingested from the data collector.
action_threat_ids
STRING
Threat IDs
additional_info
STRING
Additional information for any event that occurred (GlobalProtect).
agent_content_version
STRING
The agent content version.
agent_external_ip
STRING
External IP of the agent reporting this event.
agent_host_boot_time
INTEGER
Last time this host was started in epoch time.
agent_hostname
STRING
Hostname of the agent.
agent_id
STRING
A unique identifier per agent.
agent_install_type
INTEGER
Agent installation type with the following possible values: 0 - Standard agent 1 - Virtual Desktop Infrastructure (VDI) instance 2 - Virtual Desktop Infrastructure (VDI) golden image 4 - Temporary session 5 - Light agent
agent_interface_map
RECORD
Agent interface maps (IPs and Mac).
agent_ip_addresses
STRING
All IPv4 interface addresses.
agent_ip_addresses_v6
STRING
All IPv6 interface addresses.
agent_is_vdi
BOOLEAN
Indicates whether or not the agent is a VDI agent.
agent_mac_addresses
RECORD
Mac addresses assigned to all interfaces for this agent.
agent_os_sub_type
STRING
A lengthier description of the operating system (OS) type.
agent_os_type
INTEGER
Windows = 1 MacOS = 2 Linux = 4
agent_request_time
agent_session_start_time
INTEGER
Indicates when the agent was started.
agent_status_component
STRING
Gives the name of the endpoint detection and response (EDR) filter that was updated.
agent_version
STRING
The agent version.
associated_event_ids
STRING
associated_mac
STRING
Associated mac addresses.
association_strength
INTEGER
Indicates whether an agent_id includes an associated value using this enum mapping: 10 IP Address 20 MAC 30 Hardware ID 35 Collector ID 40 Agent ID 45 Collector Event Data 50 Event Data
auth_client
STRING
The client-side host.
auth_client_type
STRING
Type of device that the client operated from, such as a computer.
auth_correlation_id
STRING
Identifies events from seperate sessions that occurred together as part of an operation.
auth_domain
STRING
User-side domain name.
auth_identity
STRING
Client-side identification.
auth_identity_display_name
STRING
Display name of the authentication actor.
auth_identity_id
STRING
Identity \ Principal ID
auth_identity_sid
STRING
Identity SID
auth_is_interactive
BOOLEAN
True: Interactive sign-ins, where a user manually signs in using their username and password. False: Non-interactive sign-ins, such as a service-to-service authentication.
auth_method
STRING
Auth method, such as a publickey and password.
auth_mfa_needed
BOOLEAN
Indicates whether or not a Multi-factor authentication (MFA) is required.
auth_normalized_user
RECORD
Normalized user information.
auth_outcome
STRING
Authenticaion attempt outcome as either "sucess", "fail", "unknown", "SKIPPED", "ALLOW", "DENY", or "CHALLENGE".
auth_outcome_reason
STRING
Event success status description.
auth_server
STRING
Server-side host.
auth_service
STRING
Authentication service name.
auth_service_sid
STRING
Service SID
auth_target
STRING
Authentication target host.
auth_target_id
STRING
Target \ Resource ID
azure_ad_resource_display_name
STRING
Display name of the Azure AD resource (authentication server).
azure_ad_resource_id
STRING
Resource ID
azure_ad_resource_tenant_id
STRING
Resource tenant ID.
azure_authentication_info
azure_authentication_risk_info
backtrace_identities
RECORD
cef_device_product
STRING
Extracted CEF product.
cef_device_vendor
STRING
Extracted CEF vendor.
cef_device_version
STRING
Extracted CEF device version.
cef_extension
STRING
Extracted CEF extension.
cef_severity
STRING
Extracted CEF severity.
cef_signature_id
STRING
Extracted CEF signature ID.
cef_version
INTEGER
Extracted CEF version.
checkpoint_vpn_data
cisco_vpn_data
client_version
INTEGER
The endpoints GlobalProtect version.
client_version_str
clipboard_data_size
INTEGER
Size of data.
clipboard_data_type
INTEGER
CF_UNICODETEXT, CF_BITMAP
clipboard_source_iid
STRING
IID of the source process of the copied data.
cloud_entity
RECORD
Cloud provider information on the source IP of the activity.
customerId
STRING
Extracted customer ID.
device_id
RECORD
device_name
dfe_labels
STRING
Story label
directionality_strength
dns_query_items
RECORD
List of all the request items (name and type).
dns_query_name
STRING
DNS request name.
dns_query_name_domain_randomness
RECORD
Domain randomness score.
dns_query_type
STRING
DNS query type.
dns_reply_code
STRING
0 -> No error 1 -> Format Error 2 -> Server Failure 3 -> Non-Existent Domain 4 -> Not Implemented 5 -> Query Refused 6 -> Name Exists when it should not 7 -> RR Set Exists when it should not 8 -> RR Set that should exist does not 9 -> Server Not Authoritative for zone 10 -> Name not contained in zone 16 -> Bad OPT Version 16 -> TSIG Signature Failure 17 -> Key not recognized 18 -> Signature out of time window 19 -> Bad TKEY Mode 20 -> Duplicate key name 21 -> Algorithm not supported 22 -> Bad Truncation
dns_reply_codes
RECORD
DNS reply codes for the DNS query.
dns_resolutions
RECORD
DNS resolutions for query. Comprised of the Resource Record name, type, and value for each resolution item.
dst_action_as_data
RECORD
ASN data from the destination of the network activity.
dst_action_boot_time
INTEGER
Destination computer boot time in ms since the last epoch time.
dst_action_country
STRING
Destination country of the action.
dst_action_external_hostname
STRING
The hostname Cortex XDR/XSIAM connect to. For a proxy connection, this value differs from the action_remote_ip.
dst_action_external_hostname_domain_randomness
RECORD
Domain randomness score.
dst_action_external_port
INTEGER
The port Cortex XDR/XSIAM connects to. For a proxy connection, this value can differ from the action_remote_port.
dst_action_location
RECORD
Geolocation information of the destination IP.
dst_action_powered_off
BOOLEAN
True, if the computer is powered off, such as suspend or hibernate. False, otherwise.
dst_action_url_category
STRING
Next-Generation Firewall (NGFW) URL category.
dst_action_user_agent
STRING
The user agent used by an actor to perform an action.
dst_action_user_is_local_session
BOOLEAN
Indicates whether or not the user login from a remote computer or locally.
dst_action_user_session_id
INTEGER
Session ID of the action.
dst_action_user_status
INTEGER
Same as the event sub-type.
dst_action_user_status_sid
STRING
Security identifier (SID) of the user.
dst_action_username
STRING
Name of the destination user.
dst_agent_content_version
STRING
Agent content version.
dst_agent_external_ip
STRING
The IP that the destination agent reported this data.
dst_agent_host_boot_time
INTEGER
Host boot time in epoch time.
dst_agent_hostname
STRING
Agent hostname
dst_agent_id
STRING
Agent ID
dst_agent_install_type
INTEGER
Type of agent installation: 0 - Standard agent 1 - VDI instance 2 - VDI golden image 4 - Temporary session 5 - Light agent
dst_agent_interface_map
RECORD
Agent interface maps (IPs and Mac)
dst_agent_ip_addresses
STRING
Agent IPv4 addresses.
dst_agent_ip_addresses_v6
STRING
Agent IPv6 addresses.
dst_agent_is_vdi
BOOLEAN
Indicates whether or not the agent is a VDI installation.
dst_agent_os_sub_type
STRING
A lengthier description of the Operating System (OS) type.
dst_agent_os_type
INTEGER
Agent Operating System types: Windows = 1 MacOS = 2 Linux = 4
dst_agent_request_time
dst_agent_session_start_time
INTEGER
When the agent was started.
dst_agent_status_component
STRING
dst_agent_version
STRING
Agent version
dst_associated_mac
STRING
Associated MAC address.
dst_association_strength
INTEGER
Specifies whether an agent_id includes an associated value, using this enum mapping: 0 = No association 10 = IP Address 15 = Kerberos 20 = MAC 30 = Hardware ID 35 = Collector ID 40 = Agent ID 45 = Collector Event Data 50 = Event Data
dst_causality_actor_primary_normalized_user
RECORD
A normalized user for the causality chain.
dst_cloud_entity
RECORD
Cloud provider information on the destination IP of the activity.
dst_device_id
dst_event_utc_diff_minutes
INTEGER
The difference in minutes of the original timestamp from UTC, which identifies the agent's original time zone.
dst_host_metadata_domain
STRING
Domain of the host.
dst_host_metadata_hostname
STRING
Hostname
dst_host_metadata_interface_map
RECORD
Agent interface maps (IPs and Mac)
dst_is_internal_ip
BOOLEAN
Indicates whether or not the source IP is outside the private range.
dst_mac
STRING
MAC address
dst_manifest_file_version
INTEGER
dst_tcp_flags
INTEGER
TCP flags
dst_trapsId
STRING
DEPRECATED
dst_ttl
INTEGER
The closest time-to-live (TTL) preceding / following the sensor.
dst_user_id
STRING
Windows: Primary user token of the executed binary. Unix: Effective UID of the executed binary.
dst_xdr_pro_lite
BOOLEAN
Indicates whether or not the destination agent is running XDR Pro (not XTH).
dynamic_event_int_map
RECORD
DEPRECATED
dynamic_event_string_map
RECORD
Same as dynamic_event_int_map, only those are string values.
event_address_code_symbol
STRING
event_address_mapped_image_path
STRING
Windows: DLL path for the address (in process address-space) this event refers to. For example, in thread-start events, this is the path of the DLL the thread was started in.
event_allocation_base_shellcode_buffer
STRING
Hexlified buffer of shellcode at the base of the allocation of the event associated buffer.
event_call_region_base_address
INTEGER
Call region base address related to the event.
event_call_region_shellcode_buffer
STRING
Hexlified buffer of shellcode at the call region.
event_causality_mark_of_cain
INTEGER
Indicates whether a security event, such as BTP and static analysis, was raised in this causality. kNotification (1) - A security event has occurred and has NOT been prevented. kPrevention (2) - A security event has occurred but was (partially or fully) prevented.
event_direct_syscall_ip_mapped_file_path
STRING
When the event is a direct syscall, this field contains the DLL that the syscall originated from.
event_id
STRING
Event identifier
event_impersonation_status
INTEGER
This is equivalent to the event_is_impersonated field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 Impersonated = 1 Not-Impersonated = 2
event_invalidity_field
STRING
Set by the preprocessor when detecting that an event is invalid. The name of the field which caused the event to be invalid.
event_is_boot_replay
BOOLEAN
A boolean value that is true during the the first replay.
event_is_duplicated_replay
BOOLEAN
A boolean value that is true if the event was already sent before and another replay sends this event again.
event_is_impersonated
BOOLEAN
Windows: Indicates whether or not the thread performing the event is impersonating.
event_is_replay
BOOLEAN
Indicates whether or not the event is part of the system state replay sent when the agent is started.
event_is_simulated
BOOLEAN
Indicates whether or not this event was simulated by the TMS.
event_page_base_shellcode_buffer
STRING
Hexlified buffer of shellcode at the base of the page of the event associated buffer.
event_resolved_stack_trace
STRING
Stack trace related to the event.
event_rpc_func_opnum
INTEGER
Integer identifying the function being called.
event_rpc_interface_uuid
STRING
UUID identifying the interface.
event_rpc_interface_version_major
INTEGER
Major version of the remote procedure call (RPC) interface.
event_rpc_interface_version_minor
INTEGER
minor version of the remote procedure call (RPC) interface.
event_rpc_protocol
INTEGER
Enum representing the remote procedure call (RPC) protocol: LocalRpc (ALPC port) = 0 Tcp = 1 NamedPipes = 2 Http = 3
event_shellcode_address
INTEGER
The address of the shellcode in the usermode callstack.
event_source_bitmask
INTEGER
Bitmask of the sources involved in producing the event: Simulated - 0x01 Kernel-Module - 0x02 EBPF - 0x04 Fanotify - 0x08 Path-Resolved - 0x10
event_sub_type
INTEGER
This field is updated based on the event type defined in the event_type field. For each event type, there are multiple event sub types. To see the possible values for the event_type and event_sub_type, create an XQL query with a filter stage, which autocompletes the values.
event_thread_context
STRING
A string representing a JSON array containing thread specific context. Note: From XDR agent 8.2, this field is only relevant for office macros.
event_timestamp
INTEGER
Integer indicating when the event occurred.
event_timestamp_original
INTEGER
Event timestamp in epoch time.
event_type
INTEGER
A unique identifier of the event type: Process = 1 Network = 2 File = 3 Registry = 4 Injection = 5 LoadImage = 6 UserStatusChange = 7 TimeChange = 8 Thread = 9 Causality = 10 HostStatusChange = 11 AgentStatusChange = 12 InternalStatistics = 13 ProcessHandle = 14 WindowsEventLog = 15 EpmStatus = 16 MetadataChange = 17 SystemCall = 18 Device = 19 HostFirewall = 23
event_user_presence
BOOLEAN
Indicates whether or not there was a physical user presence on the machine. Windows: The value is"true" if the user session was unlocked during the event.
event_user_presence_status
INTEGER
This is equivalent to the event_user_presence field, but sometimes the status is unknown. The other field can't account for this as it's a boolean field. Unknown = 0 User not present = 1 User present = 2
event_user_thread_context_ip
INTEGER
The instruction pointer at the moment the syscall was made.
event_user_thread_context_ip_in_native_ntdll
BOOLEAN
Indicates whether or not the IP in the trapframe when in the middle of a syscall was pointing to ntdll.
event_user_thread_context_is_heavens_gate
BOOLEAN
Indicates whether or not the user stack pointer is not inside the x64 stack limits, but was inside the x86 stack limits for a wow64 process.
event_user_thread_context_is_stack_pivot
BOOLEAN
Indicates whether or not the RSP in the trapframe was not inside the thread stack limits.
event_user_thread_context_sp
INTEGER
The stack pointer at the moment the syscall was made.
event_utc_diff_minutes
INTEGER
The difference in minutes of the original timestamp from UTC.
event_validity_enum
INTEGER
An enum set by the preprocessor when detecting that an event is invalid: 1 - valid 2 - invalid due to future timestamp field. 3 - invalid due to an "old" timestamp field that exceeds the host's boot time.
event_version
INTEGER
Version of the event structure, where each change increases the version.
event_versions
INTEGER
Event version for this event.
execution_actor_causality_id
STRING
Causality ID of the parent which executed the terminated process instance.
execution_actor_instance_id
STRING
Instance ID of the parent which executed the terminated process instance.
facility
STRING
file_data
fw_dst_normalized_user
RECORD
Normalized user information.
fw_identities
RECORD
DEPRECATED
fw_is_dup_log
INTEGER
fw_log_subtypes
STRING
fw_log_types
STRING
fw_src_normalized_user
RECORD
Normalized user information.
fw_time_generated
INTEGER
Equivalent to the event_timestamp.
fw_traffic_flags
INTEGER
Protocol traffic flags as seen on the Next-Generation Firewall (NGFW).
generatedTime
TIMESTAMP
Equivalent to the event_timestamp.
global_protect_data
hardware_id
STRING
Unique identifier GlobalProtect assigned to the host.
host_metadata_domain
STRING
Domain of the host.
host_metadata_hostname
STRING
Hostname
host_metadata_interface_map
RECORD
Agent interface maps (IPs and Mac).
http_content_type
STRING
Content-type header of the HTTP traffic.
http_data
RECORD
HTTP log data.
http_data_is_trimmed
BOOLEAN
Indicates whether the HTTP data was too long that it was trimmed by the Next-Generation Firewall (NGFW).
http_method
STRING
0 = UNKNOWN_METHOD 1 = GET 2 = POST 3 = CONNECT 4 = HEAD 5 = PUT 6 = DELETE 7 = OPTIONS
http_referer
STRING
HTTP Referer header.
http_req_before_method
STRING
http_req_content_type_header
STRING
HTTP content type header.
http_req_host_header
STRING
HTTP host header.
http_req_referer_header
STRING
HTTP Referer header.
http_req_uri
STRING
HTTP request URI.
http_req_user_agent_header
STRING
HTTP user agent header.
http_rsp_code
INTEGER
HTTP response code.
http_rsp_content_type_header
STRING
HTTP response content type header.
http_rsp_filename
STRING
HTTP response filename.
http_server
STRING
HTTP server
http_status_code
INTEGER
HTTP status code.
hwnd
INTEGER
The foreground window.
icmp_code
INTEGER
ICMP protocol request code.
icmp_original_length
INTEGER
Internet Control Message Protocol (ICMP) payload length.
icmp_type
INTEGER
ICMP protocol request type.
insert_timestamp
TIMESTAMP
Ingestion timestamp
is_disintegrated
BOOLEAN
Indicates whether or not the story was disintegrated.
is_internal_ip
BOOLEAN
Indicates whether or not the source IP is outside the private range.
krb_tgs_data
RECORD
Kerberos Ticket Granting Service (TGS) log data.
krb_tgt_data
RECORD
Kerberos Ticket Granting Service (TGS) log data.
ldap_data
RECORD
LDAP log data.
login_data
RECORD
Windows Event Log login data.
login_data_dst_normalized_user
RECORD
Destination user CIE resolution information.
login_data_dst_outbound_normalized_user
RECORD
Destination outbound user DSS resolution information.
login_data_src_normalized_user
RECORD
Source user CIE resolution information.
non_standard_dport
INTEGER
This field is a boolean represented as an Integer. Indicates whether or not the destination port is a non-standard port based on Next-Generation Firewall (NGFW) logic
ntlm_auth_data
RECORD
NTLM log data.
one_login_data
other_json
DEPRECATED
packet
STRING
Packet payload excluding TCP/IP header. Only valid for event_sub_type = 17 (raw_data)
related_alerts
serverTime
TIMESTAMP
Timestamp of the event displayed on the server side.
ssl_data
RECORD
SSL log data.
ssl_req_chello_sni_sample
STRING
SNI domain obtained from SSL protocol parsing.
sso_debug_data
STRING
Okta debug info, which includes protocol informaiton, URIs, and more.
sso_display_message
STRING
Single Sign-on (SSO) event description.
sso_event_type
INTEGER
Single Sign-On (SSO) event type as obtained by the original SSO provider.
sso_severity
STRING
Severity as reported: DEBUG, INFO, WARN, ERROR
story_id
STRING
ID of the story.
story_id_original
DEPRECATED
story_publish_timestamp
INTEGER
Story publishing timestamp in epoch time.
story_version
FLOAT
Story version
syscall_action_etw_based
BOOLEAN
Indicates whether or not the syscall collected is from Windows ETW.
syscall_action_int_params
STRING
Integer parameters from syscalls in a JSON format.
syscall_action_stack_ptr
STRING
syscall_action_string_params
STRING
String parameters from syscalls in a JSON format.
tcp_flags
INTEGER
TCP Flags
title
STRING
Title of top_level_hwnd.
top_level_hwnd
INTEGER
The top level window of the foreground window.
trapsId
STRING
DEPRECATED
ttl
INTEGER
IP Protocol time-to-live (TTL) obtained from the source.
tunnel_type
STRING
The type of tunnel.
uri
STRING
Threat URI
user_generic_value1
INTEGER
A bitmap that can be set in the YAML. The first bit indicates whether an operation is in the GUI or not.
user_generic_value2
INTEGER
An integer that can be set in the YAML. It is used to indicate Yara rule IDs for windows web shells.
user_id
STRING
Windows: User SID Unix: UID
uuid
STRING
Equivalent to the 'event_id'.
vendor
STRING
Log vendor
vpn_event_description
STRING
The name of the GlobalProtect event.
vpn_server
STRING
VPN server name or IP.
vpn_service
STRING
VPN service name.
xdr_pro_lite
BOOLEAN
Indicates whether or not the agent is XDRProNG and sends fewer events.
zip_id
STRING
DEPRECATED
zscaler_vpn_data
Last updated
Was this helpful?
