File Log
Normalize file logs in Genian EDR.
Type | Field | Display Name |
---|---|---|
DATE | _time | Time |
STRING | event_type | Event type |
STRING | event_subtype | Event subtype |
INT | important | Important level |
IP | host_ip | Host IP |
STRING | nt_domain | NT domain |
STRING | hostname | Hostname |
STRING | tag | Tag |
STRING | image | Process name |
STRING | domain | Domain |
STRING | image_path | Process path |
IP | remote_ip | Remote IP |
INT | remote_port | Remote port |
STRING | driver_type | Driver type |
STRING | driver_type2 | Driver type #2 |
STRING | final_name | Final file name |
STRING | file_name | File name |
STRING | file_name2 | File name #2 |
STRING | file_type | File type |
LONG | file_size | File size |
STRING | file_path | File path |
STRING | file_path2 | File path #2 |
DATE | file_ctime | File creation time |
DATE | file_mtime | File modification time |
STRING | md5 | MD5 |
STRING | sha256 | SHA256 |
BOOL | check_flag | Is checked |
BOOL | uncertain | Uncertain |
STRING | logon_id | Logon ID |
INT | pid | PID |
STRING | pguid | Process GUID |
STRING | device_id | Device ID |
LONG | event_seq | Event sequence |
LONG | related_event_seq | Related event sequence |