SentinelOne

다운로드 31
업데이트 2025. 2. 19.

SentinelOne 로그인 이벤트

event.category = logins

번호타입필드이름설명
1날짜_time시각예: 2026-05-03 01:28:16
2날짜event_time이벤트시각예: 2026-05-03 01:28:16
3문자열site_name사이트명예: ACME
4문자열hostname호스트명예: DESKTOP-EXAMPLE
5문자열user계정예: demouser0001@mail.com
6문자열event_type이벤트유형예: Login, Logout
7문자열image이미지예: svchost.exe
8문자열cmd_line명령줄예: C:\Windows\system32\svchost.ex...
9IP 주소src_ip출발지IP예: 192.0.2.10
10문자열login_type로그인유형예: INTERACTIVE, UNLOCK, NETWORK
11문자열nt_domainNT도메인예: WORKGROUP
12문자열target_nt_domain대상NT도메인예: MicrosoftAccount
13불리언is_admin_login관리자로그인여부예: true
14불리언login_success로그인성공여부예: true
15문자열nt_userNT계정예: DESKTOP-EXAMPLE$
16문자열login_target_sid대상계정SID예: S-1-5-21-1214884534-2691577776...
1732비트 정수login_session_id로그인세션ID예: 0
18문자열parent_image부모이미지예: services.exe
19문자열parent_cmd_line부모명령줄예: C:\Windows\system32\services.exe
20문자열event_category이벤트분류예: logins
21문자열event_name이벤트이름예: WINLOGONATTEMPT, WINLOGOFF
22문자열endpoint_type단말유형예: laptop
23문자열os_familyOS유형예: windows
24문자열os_nameOS이름예: Windows 11 Home
25문자열os_revOS리비전예: 26200
26문자열user_sid계정SID예: S-1-5-18
27날짜parent_start_time부모시작일시예: 2026-05-02 14:02:24
2864비트 정수ppidPPID예: 1192
29문자열parent_user부모계정예: DESKTOP-EXAMPLE\demouser
30MD5parent_image_md5부모이미지MD516진수 32자
31SHA1parent_image_sha1부모이미지SHA116진수 40자
32SHA256parent_image_sha256부모이미지SHA25616진수 64자
33불리언is_parent_image_signed부모이미지서명여부예: true
34문자열parent_image_path부모이미지경로예: C:\Windows\System32\services.exe
35문자열parent_image_signer부모디지털서명예: MICROSOFT WINDOWS PUBLISHER
36문자열parent_integrity_level부모무결성수준예: SYSTEM
37문자열parent_subsystem부모서브시스템예: SYS_WIN32
38날짜start_time시작일시예: 2026-05-02 14:02:25
3964비트 정수pidPID예: 2532
40문자열image_user이미지계정예: DESKTOP-EXAMPLE\demouser
41문자열image_display_name이미지표시이름예: Host Process for Windows Services
4264비트 정수image_size이미지크기바이트 단위
43MD5image_md5이미지MD516진수 32자
44SHA1image_sha1이미지SHA116진수 40자
45SHA256image_sha256이미지SHA25616진수 64자
46문자열image_path이미지경로예: C:\Windows\System32\svchost.exe
47문자열image_signer디지털서명예: MICROSOFT WINDOWS
48불리언is_image_signed이미지서명여부예: true
49불리언is_sign_verified서명검증여부예: true
50문자열integrity_level무결성수준예: SYSTEM
51문자열subsystem서브시스템예: SYS_WIN32
52문자열target_user대상계정예: demouser0001@mail.com
53문자열agent_ver에이전트버전예: 25.1.3.334
54문자열agent_uuid에이전트식별자16진수 32자
5532비트 정수session_id세션ID예: 0
56문자열account_id계정ID예: 1234567890123456789
57문자열account_name계정명예: Sentinel Labs PTE Korea
58문자열mgmt_id관리ID예: 365
59문자열mgmt_url관리URL예: apne1-9999-xxx.sentinelone.net
60문자열site_id사이트ID예: 2387424777214565688
61문자열group_id그룹ID예: FA509D275BA10626
62문자열event_id이벤트IDULID 26자 + _순번
63문자열trace_id추적IDULID 26자 (Crockford Base32)
64문자열packet_id패킷ID16진수 32자
65문자열parent_process_uuid부모프로세스식별자16진수 16자
66문자열process_uuid프로세스식별자16진수 16자
67문자열parent_storyline부모스토리라인16진수 16자
68문자열storyline스토리라인16진수 16자
69문자열process_unique_key프로세스고유키16진수 16자