Schema: General
Cross-cutting event fields including event type, provider, activity name, status, severity, logon types, privileges, MFA flags, user/group identifiers, resource names, and email threat indicators.
29 fields available
[← Back to Schema Field Reference](schema-field-reference-guide.md)
activity_name
activity_nameActivity name
Providers: okta,cloudtrail
category_name
category_nameCategory name
Providers: okta
email.threat.confidence_level
email.threat.confidence_levelDefender per-threat-family confidence verdict; a Phish=High gate bounds delivered-phish detection volume
Providers: azure_event_hub
event.provider
event.providerProvider name for the event source. Known values: crowdstrike, sentinel_one, elastic, jamf_protect, microsoft_defender, okta, duo, cloudtrail.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail,gcp_pubsub
event.type
event.typeEvent type identifier as reported by the source. Format and semantics vary significantly by provider: CrowdStrike (event_simpleName like ProcessRollup2V19, DnsRequestV5), Microsoft Defender (ActionType like ProcessCreated, FileCreated), Microsoft Entra (activityDisplayName like 'Add user', 'Update user'), CloudTrail (eventName like CreateUser, AssumeRole), Elastic (event.category like process, network). Maps to the raw telemetry event name before normalization. Use information_model_name for normalized event categories across providers.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail,azure_event_hub,gcp_pubsub
finding_tags
finding_tagsArray of tags associated with the finding for categorization and filtering.
Providers: falco,jamf_protect
group.name
group.nameName of the group
Providers: crowdstrike,okta,cloudtrail
group.uid
group.uidUnique identifier of the group (e.g. IAM group ID)
Providers: crowdstrike,okta,cloudtrail
is_admin_operation
is_admin_operationEvent-level flag from source telemetry indicating the recorded action is classified as an administrative operation. Does not imply the actor has standing admin privileges. NOCSF extension.
Providers: microsoft_defender
is_anonymous_proxy
is_anonymous_proxyEvent-level enrichment flag from source telemetry indicating the source IP is classified as an anonymous proxy. Null means unknown/unavailable. NOCSF extension.
Providers: microsoft_defender
is_mfa
is_mfaWhether MFA was used for authentication. Jamf: populated for TouchID auth events only.
Providers: okta,duo,jamf_protect,cloudtrail
logon_type
logon_typeType of logon session. Known values: Interactive (local console), Network (SMB/file share), RemoteInteractive (RDP), Remote (SSH), Local (OD auth), Service, Batch (scheduled task), Unlock, CachedInteractive (cached domain creds), NewCredentials (RunAs /netonly), NetworkCleartext.
Providers: microsoft_defender,crowdstrike,jamf_protect
metadata.product.name
metadata.product.nameName of the security product that generated the finding.
Providers: falco
metadata.product.vendor_name
metadata.product.vendor_nameVendor name of the security product (e.g. sysdig for Falco).
Providers: falco
metadata.product.version
metadata.product.versionVersion of the vendor agent or sensor that produced the event (Jamf Protect host.protectVersion, SentinelOne agent.version, Defender ClientVersion, CrowdStrike ConfigBuild). Lets fleet-upgrade timing be queried rather than reconstructed from raw payloads, which are retained only ~3 days. Defender caveat: a real sensor build appears only where OnboardingStatus is Onboarded, form 10.
Providers: jamf_protect,sentinel_one,azure_event_hub,crowdstrike
nebulock_im_source
nebulock_im_sourceInformation model source identifier. Known values: im-process_create, im-file_create, im-dns_request, im-network_connection, im-directory_create, im-mount, im-unmount, im-remount, im-peripheral, im-api_activity, im-authentication, im-authorize_session, im-detection_finding, im-web_resource_access_activity.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail
privileges
privilegesList of privileges as a string
Providers: okta
provider
providerConvenience duplicate of nebulock_provider_name. Known values: crowdstrike, sentinel_one, okta, elastic, jamf_protect, microsoft_defender, duo, cloudtrail.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail
resource.account_uid
resource.account_uidAWS account ID owning the resource
Providers: cloudtrail
resource.name
resource.nameName of the resource being acted upon
Providers: cloudtrail,gcp_pubsub
resource.type
resource.typeAWS resource type from CloudTrail resources array
Providers: cloudtrail,gcp_pubsub
resource.uid
resource.uidUnique identifier of the resource (e.g. requestParameters.arn)
Providers: cloudtrail,microsoft_defender,azure_event_hub
service.name
service.nameName of the service or application. Known values from sample: Lever, Salesforce.com, OpenID Connect Client, Terraform Cloud, Active Directory.
Providers: okta,duo
service.uid
service.uidThe id of the application we are using
Providers: okta
severity
severitySeverity level of the event. Okta: INFO, WARNING for identity and access management events like policy changes, user modifications, authentication attempts. Values indicate risk/impact level of the activity.
Providers: okta
status
statusstatus of the event (for any IM type, auth for example is SUCCESS, CHALLENGE, ET)
Providers: okta,duo,cloudtrail,jamf_protect,azure_event_hub,microsoft_defender,gcp_pubsub
user.email
user.emailEmail address of the target user being acted upon (not the actor). Okta/CloudTrail: typically the user whose account is being created, modified, or accessed. For actor email, see actor.user.email_addr.
Providers: okta,cloudtrail,microsoft_defender,azure_event_hub
user.name
user.nameName of the target user being acted upon (e.g. requestParameters.userName, od_create_user.user_name)
Providers: crowdstrike,cloudtrail,jamf_protect
user.uid
user.uidUnique identifier of the target user (e.g. IAM user ID)
Providers: crowdstrike,cloudtrail
Updated 1 day ago