Predefined search fields and values
The following tables display the search fields with predefined values, grouped by category:
Field name | Predefined values |
---|---|
file.operation |
|
file.attribute_operation |
|
file.item_type |
|
Field name | Predefined values |
---|---|
alert.type |
|
alert.mark |
|
alert.scan_type |
|
alert.actions_taken |
|
Field name | Predefined values |
---|---|
network.direction |
|
Field name | Predefined values |
---|---|
process.integrity_level |
|
process.parent_integrity_level |
|
process.access_privileges |
|
process.parent_access_privileges |
|
Field name | Predefined values |
---|---|
registry.operation |
|
registry.type |
|
Field name | Predefined values |
---|---|
user.type |
|
Field name | Predefined values |
---|---|
email.logon_type |
|
Field name | Predefined values |
---|---|
other.event_name | |
other.os |
|
other.event_type |
|
other.detection_class |
|
other.sensor_name |
|
other.arch |
|
other.compliance_center_event |
|
other.result_status |
|