File Log
Normalize file logs in Genian EDR.
| Type | Field | Display Name |
|---|---|---|
| DATE | _time | Time |
| STRING | event_type | Event type |
| STRING | event_subtype | Event subtype |
| INT | important | Important level |
| IP | host_ip | Host IP |
| STRING | nt_domain | NT domain |
| STRING | hostname | Hostname |
| STRING | tag | Tag |
| STRING | image | Process name |
| STRING | domain | Domain |
| STRING | image_path | Process path |
| IP | remote_ip | Remote IP |
| INT | remote_port | Remote port |
| STRING | driver_type | Driver type |
| STRING | driver_type2 | Driver type #2 |
| STRING | final_name | Final file name |
| STRING | file_name | File name |
| STRING | file_name2 | File name #2 |
| STRING | file_type | File type |
| LONG | file_size | File size |
| STRING | file_path | File path |
| STRING | file_path2 | File path #2 |
| DATE | file_ctime | File creation time |
| DATE | file_mtime | File modification time |
| STRING | md5 | MD5 |
| STRING | sha256 | SHA256 |
| BOOL | check_flag | Is checked |
| BOOL | uncertain | Uncertain |
| STRING | logon_id | Logon ID |
| INT | pid | PID |
| STRING | pguid | Process GUID |
| STRING | device_id | Device ID |
| LONG | event_seq | Event sequence |
| LONG | related_event_seq | Related event sequence |