Genian EDR

Download 35
Last updated Aug 6, 2023

Network log

Normalize network connection logs in Genian EDR.

TypeFieldDisplay Name
DATE_timeTime
STRINGevent_typeEvent type
STRINGevent_subtypeEvent subtype
INTimportantImportant level
IPhost_ipHost IP
STRINGnt_domainNT domain
STRINGhostnameHostname
STRINGtagTag
STRINGimageProcess name
STRINGimage_pathProcess path
STRINGdirectionDirection
IPlocal_ipLocal IP
INTlocal_portLocal port
IPremote_ipRemote IP
INTremote_portRemote port
STRINGprotocolProtocol
INTis_connectedIs connected
LONGsent_bytesSent bytes
LONGrcvd_bytesReceived bytes
INTconn_countConnection count
INTdisconn_countDisconnection count
INTdisconn_flagDisconnection flag
DATEdisconn_timeDisconnection time
STRINGlogon_idLogon ID
INTpidPID
STRINGpguidProcess GUID
STRINGdevice_idDevice ID
LONGevent_seqEvent sequence