File Log
Normalize file logs in Genian EDR.
| Type | Field | Display Name | 
|---|---|---|
| DATE | _time | Time | 
| STRING | event_type | Event type | 
| STRING | event_subtype | Event subtype | 
| INT | important | Important level | 
| IP | host_ip | Host IP | 
| STRING | nt_domain | NT domain | 
| STRING | hostname | Hostname | 
| STRING | tag | Tag | 
| STRING | image | Process name | 
| STRING | domain | Domain | 
| STRING | image_path | Process path | 
| IP | remote_ip | Remote IP | 
| INT | remote_port | Remote port | 
| STRING | driver_type | Driver type | 
| STRING | driver_type2 | Driver type #2 | 
| STRING | final_name | Final file name | 
| STRING | file_name | File name | 
| STRING | file_name2 | File name #2 | 
| STRING | file_type | File type | 
| LONG | file_size | File size | 
| STRING | file_path | File path | 
| STRING | file_path2 | File path #2 | 
| DATE | file_ctime | File creation time | 
| DATE | file_mtime | File modification time | 
| STRING | md5 | MD5 | 
| STRING | sha256 | SHA256 | 
| BOOL | check_flag | Is checked | 
| BOOL | uncertain | Uncertain | 
| STRING | logon_id | Logon ID | 
| INT | pid | PID | 
| STRING | pguid | Process GUID | 
| STRING | device_id | Device ID | 
| LONG | event_seq | Event sequence | 
| LONG | related_event_seq | Related event sequence |