AhnLab EPP

Download 244
Last updated Mar 5, 2024

Ahnlab EPP EDR Windows Event

EDR_OS_EVENT Event

TypeFieldDisplay NameDescription
Date_timeTime
Stringevent_idEvent ID
IP addresssrc_ipSource IP
Stringsrc_macSource MAC
StringhostnameHostname
StringuserAccount
Stringdept_nameDepartment
Stringuser_nameName
StringproviderEvent providere.g. Microsoft-Windows-Security-Auditing
StringchannelEvent channele.g. Security
Integerevent_idxEvent Noe.g. 15
StringlevelLevel
StringtaskTaske.g. Logon
StringmsgMessage
Stringplatform_idPlatform IDe.g. WINDOWS_10_X64
StringkeywordsKeyword
StringopcodeOpcode
Stringnode_idNode IDe.g. 7
Stringgroup_idGroup IDe.g. 8
Stringhost_idHost IDe.g. 25
Dateclient_timeClient time