Genian EDR

Download 31
Last updated Aug 6, 2023

File Log

Normalize file logs in Genian EDR.

TypeFieldDisplay Name
DATE_timeTime
STRINGevent_typeEvent type
STRINGevent_subtypeEvent subtype
INTimportantImportant level
IPhost_ipHost IP
STRINGnt_domainNT domain
STRINGhostnameHostname
STRINGtagTag
STRINGimageProcess name
STRINGdomainDomain
STRINGimage_pathProcess path
IPremote_ipRemote IP
INTremote_portRemote port
STRINGdriver_typeDriver type
STRINGdriver_type2Driver type #2
STRINGfinal_nameFinal file name
STRINGfile_nameFile name
STRINGfile_name2File name #2
STRINGfile_typeFile type
LONGfile_sizeFile size
STRINGfile_pathFile path
STRINGfile_path2File path #2
DATEfile_ctimeFile creation time
DATEfile_mtimeFile modification time
STRINGmd5MD5
STRINGsha256SHA256
BOOLcheck_flagIs checked
BOOLuncertainUncertain
STRINGlogon_idLogon ID
INTpidPID
STRINGpguidProcess GUID
STRINGdevice_idDevice ID
LONGevent_seqEvent sequence
LONGrelated_event_seqRelated event sequence