Schema: General

Cross-cutting event fields including event type, provider, activity name, status, severity, logon types, privileges, MFA flags, user/group identifiers, resource names, and email threat indicators.

29 fields available

[← Back to Schema Field Reference](schema-field-reference-guide.md)


activity_name

Activity name

Providers: okta,cloudtrail


category_name

Category name

Providers: okta


email.threat.confidence_level

Defender per-threat-family confidence verdict; a Phish=High gate bounds delivered-phish detection volume

Providers: azure_event_hub


event.provider

Provider name for the event source. Known values: crowdstrike, sentinel_one, elastic, jamf_protect, microsoft_defender, okta, duo, cloudtrail.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail,gcp_pubsub


event.type

Event type identifier as reported by the source. Format and semantics vary significantly by provider: CrowdStrike (event_simpleName like ProcessRollup2V19, DnsRequestV5), Microsoft Defender (ActionType like ProcessCreated, FileCreated), Microsoft Entra (activityDisplayName like 'Add user', 'Update user'), CloudTrail (eventName like CreateUser, AssumeRole), Elastic (event.category like process, network). Maps to the raw telemetry event name before normalization. Use information_model_name for normalized event categories across providers.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail,azure_event_hub,gcp_pubsub


finding_tags

Array of tags associated with the finding for categorization and filtering.

Providers: falco,jamf_protect


group.name

Name of the group

Providers: crowdstrike,okta,cloudtrail


group.uid

Unique identifier of the group (e.g. IAM group ID)

Providers: crowdstrike,okta,cloudtrail


is_admin_operation

Event-level flag from source telemetry indicating the recorded action is classified as an administrative operation. Does not imply the actor has standing admin privileges. NOCSF extension.

Providers: microsoft_defender


is_anonymous_proxy

Event-level enrichment flag from source telemetry indicating the source IP is classified as an anonymous proxy. Null means unknown/unavailable. NOCSF extension.

Providers: microsoft_defender


is_mfa

Whether MFA was used for authentication. Jamf: populated for TouchID auth events only.

Providers: okta,duo,jamf_protect,cloudtrail


logon_type

Type of logon session. Known values: Interactive (local console), Network (SMB/file share), RemoteInteractive (RDP), Remote (SSH), Local (OD auth), Service, Batch (scheduled task), Unlock, CachedInteractive (cached domain creds), NewCredentials (RunAs /netonly), NetworkCleartext.

Providers: microsoft_defender,crowdstrike,jamf_protect


metadata.product.name

Name of the security product that generated the finding.

Providers: falco


metadata.product.vendor_name

Vendor name of the security product (e.g. sysdig for Falco).

Providers: falco


metadata.product.version

Version of the vendor agent or sensor that produced the event (Jamf Protect host.protectVersion, SentinelOne agent.version, Defender ClientVersion, CrowdStrike ConfigBuild). Lets fleet-upgrade timing be queried rather than reconstructed from raw payloads, which are retained only ~3 days. Defender caveat: a real sensor build appears only where OnboardingStatus is Onboarded, form 10.

Providers: jamf_protect,sentinel_one,azure_event_hub,crowdstrike


nebulock_im_source

Information model source identifier. Known values: im-process_create, im-file_create, im-dns_request, im-network_connection, im-directory_create, im-mount, im-unmount, im-remount, im-peripheral, im-api_activity, im-authentication, im-authorize_session, im-detection_finding, im-web_resource_access_activity.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail


privileges

List of privileges as a string

Providers: okta


provider

Convenience duplicate of nebulock_provider_name. Known values: crowdstrike, sentinel_one, okta, elastic, jamf_protect, microsoft_defender, duo, cloudtrail.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,duo,cloudtrail


resource.account_uid

AWS account ID owning the resource

Providers: cloudtrail


resource.name

Name of the resource being acted upon

Providers: cloudtrail,gcp_pubsub


resource.type

AWS resource type from CloudTrail resources array

Providers: cloudtrail,gcp_pubsub


resource.uid

Unique identifier of the resource (e.g. requestParameters.arn)

Providers: cloudtrail,microsoft_defender,azure_event_hub


service.name

Name of the service or application. Known values from sample: Lever, Salesforce.com, OpenID Connect Client, Terraform Cloud, Active Directory.

Providers: okta,duo


service.uid

The id of the application we are using

Providers: okta


severity

Severity level of the event. Okta: INFO, WARNING for identity and access management events like policy changes, user modifications, authentication attempts. Values indicate risk/impact level of the activity.

Providers: okta


status

status of the event (for any IM type, auth for example is SUCCESS, CHALLENGE, ET)

Providers: okta,duo,cloudtrail,jamf_protect,azure_event_hub,microsoft_defender,gcp_pubsub


user.email

Email address of the target user being acted upon (not the actor). Okta/CloudTrail: typically the user whose account is being created, modified, or accessed. For actor email, see actor.user.email_addr.

Providers: okta,cloudtrail,microsoft_defender,azure_event_hub


user.name

Name of the target user being acted upon (e.g. requestParameters.userName, od_create_user.user_name)

Providers: crowdstrike,cloudtrail,jamf_protect


user.uid

Unique identifier of the target user (e.g. IAM user ID)

Providers: crowdstrike,cloudtrail



Did this page help you?