Schema: Network Activity

Network connections, DNS queries, HTTP requests, and TLS sessions. Includes source/destination IPs, domains, geolocation, DNS resolution chains, HTTP user agents, and TLS certificates.

37 fields available

[← Back to Schema Field Reference](schema-field-reference-guide.md)


destination.network_endpoint.domain

Domain name of the destination endpoint.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


destination.network_endpoint.ip

IP address of the destination endpoint.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


destination.network_endpoint.isp

Internet service provider associated with the destination endpoint. Mirrors source.network_endpoint.isp. Defender reports the literal "Internal" for on-premise destinations such as a domain controller. Not yet populated: the only IMs mapping it (Defender IdentityDirectoryEvents) are inactive.

Providers: Not specified


destination.network_endpoint.location.country

Country of the destination endpoint geolocation. Mirrors source.network_endpoint.location.country for events whose geolocation describes the endpoint being acted upon rather than the actor, such as Defender IdentityDirectoryEvents where the only address in the payload is the domain controller. Not yet populated: the only IMs mapping it (Defender IdentityDirectoryEvents) are inactive.

Providers: Not specified


destination.network_endpoint.mac

MAC address of the destination endpoint as observed on the local segment. Only populated when the reporting host shares a layer-2 broadcast domain with the peer; routed traffic reports the gateway MAC instead. Defender emits the sentinel values 12:34:56:78:9a:bc and 00:aa:bb:cc:dd:ee as placeholders -- exclude both when using this field.

Providers: azure_event_hub,microsoft_defender


destination.network_endpoint.port

Port number of the destination endpoint.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


destination.network_endpoint.public_ip

Public (NAT) address of the monitored endpoint that was externally scanned. Belongs to the same endpoint as destination.network_endpoint.ip, which carries its private address. OCSF has no public/NAT address attribute on network_endpoint, so this is a NOCSF extension placed on the endpoint it describes.

Providers: azure_event_hub,microsoft_defender


destination.network_endpoint.public_port

Port reached on the externally scanned public address of the monitored endpoint. Typed Int64 to match destination.network_endpoint.port.

Providers: azure_event_hub,microsoft_defender


dns.question.class

DNS query class field from the DNS protocol. C_INTERNET (IN) indicates standard internet DNS queries and is present in nearly all modern DNS requests. Other classes (CH for CHAOS, HS for Hesiod) are rare. Microsoft Defender provides human-readable names, CrowdStrike uses numeric codes.

Providers: crowdstrike,sentinel_one,microsoft_defender


dns.question.name

The domain name or hostname requested in the DNS query. Forward lookups contain FQDNs (browser.events.data.msn.com), reverse lookups contain in-addr.arpa PTR format (13.33.82.16.in-addr.arpa). This is the QUESTION section of the DNS protocol - what the client is trying to resolve.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


dns.question.type

DNS record type being queried. Common types: 1 (A/IPv4), 28 (AAAA/IPv6), 5 (CNAME), 12 (PTR/reverse lookup), 15 (MX/mail), 16 (TXT), 33 (SRV/service), 65 (HTTPS). CrowdStrike/Elastic use numeric codes, Microsoft Defender may use names. PTR queries (12) indicate reverse DNS lookups. HTTPS queries (65) are used for modern encrypted DNS resolution.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


dns.rcode

DNS response code name returned for the query, for example NOERROR, NXDOMAIN or SERVFAIL. A raised per-host NXDOMAIN rate is the primary signal for DGA and DNS tunnelling. Named rcode to match the OCSF DNS Activity class attribute.

Providers: azure_event_hub,microsoft_defender


dns_answers

Array of IP addresses (IPv4/IPv6) returned in the DNS ANSWER section. Contains the resolved IPs for A (1) and AAAA (28) record queries. Empty/null for failed queries, CNAME-only responses, or non-address record types (MX, TXT, SRV). Check dns_cnames for CNAME resolution chains. For reverse PTR lookups, this field is typically empty - the hostname is in the ANSWER section but not captured here.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


dns_cnames

Array of CNAME (Canonical Name) records in the DNS resolution chain. Shows domain aliases before final IP resolution (e.g., api.example.com → cdn.cloudprovider.com → final IPs in dns_answers). Order represents resolution chain. Useful for identifying CDN usage, domain fronting, and tracking infrastructure dependencies. Empty when query directly resolves to IPs without aliases.

Providers: crowdstrike,sentinel_one,microsoft_defender


http_request.http_method

HTTP request method. Named http_method to match the OCSF http_request object attribute.

Providers: azure_event_hub,microsoft_defender


http_request.url.path

Request URI or path from the HTTP request line. OCSF models http_request.url as a url object, so the path is addressed as url.path; url.hostname and url.query_string remain available for future mappings.

Providers: azure_event_hub,microsoft_defender


http_request.url.url_string

Absolute request URL including scheme, host and query string. Matches the OCSF url object attribute url_string. Use this rather than http_request.url.path when the source carries a full URL -- Defender Graph audit RequestUri is absolute, whereas the Zeek HTTP inspection uri is a path.

Providers: Not specified


http_request.user.name

Account name presented in HTTP authentication, for example HTTP Basic. Never contains the password.

Providers: azure_event_hub,microsoft_defender


http_request.user_agent

HTTP user agent string from the request.

Providers: okta,duo,crowdstrike,microsoft_defender,gcp_pubsub


http_response.code

HTTP response status code returned for the request. Lives on the OCSF http_response object, not http_request.

Providers: azure_event_hub,microsoft_defender


network.direction

Direction of the network traffic. Values derived during normalization (e.g., egress, ingress, loopback).

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


network.protocol

Transport protocol. Defender and CrowdStrike report protocol names, which are lowercased to tcp, udp or icmp during normalization; Defender's address-family variants (TcpV4, TcpV6, UdpV4, UdpV6, IcmpV4, IcmpV6) fold to the same value, so a filter on tcp matches all of them. Jamf Protect is different: it maps socket_protocol unchanged, so this field holds IANA protocol NUMBERS as strings for that provider -- 6 (TCP), 17 (UDP), 1 (ICMP), 58 (ICMPv6). A consumer matching on 'tcp' must handle '6' as well, or scope the query by provider. Values outside both sets pass through as the vendor emitted them -- Defender Kerberos, Jamf Apple Fabric.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


network.type

Network boundary or type classification. Known values: Loopback, Public, Private, FourToSixMapping, LinkLocal.

Providers: crowdstrike,sentinel_one,microsoft_defender


source.network_endpoint.ip

IP address of the source endpoint.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,gcp_pubsub


source.network_endpoint.isp

Internet service provider associated with the source endpoint.

Providers: okta,microsoft_defender,azure_event_hub


source.network_endpoint.location.city

City of the source endpoint geolocation.

Providers: okta


source.network_endpoint.location.country

Country of the source endpoint geolocation.

Providers: okta,microsoft_defender,azure_event_hub


source.network_endpoint.location.lat

Latitude of the source endpoint geolocation.

Providers: okta


source.network_endpoint.location.long

Longitude of the source endpoint geolocation.

Providers: okta


source.network_endpoint.location.state

Geo State of the network endpoint

Providers: okta


source.network_endpoint.mac

MAC address of the source endpoint as observed on the local segment. Only populated when the reporting host shares a layer-2 broadcast domain with the peer; routed traffic reports the gateway MAC instead. Defender emits the sentinel values 12:34:56:78:9a:bc and 00:aa:bb:cc:dd:ee as placeholders -- exclude both when using this field.

Providers: azure_event_hub,microsoft_defender


source.network_endpoint.network_proxy.ip

External/public-facing IP address of the endpoint agent as seen by the EDR cloud (NAT or proxy IP). CrowdStrike: aip field.

Providers: crowdstrike


source.network_endpoint.port

Port number of the source endpoint.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


tls.certificate.issuer

Issuer distinguished name of the server certificate. Reveals internal and rogue certificate authorities.

Providers: azure_event_hub,microsoft_defender


tls.certificate.subject

Subject distinguished name of the server certificate. Equal to tls.certificate.issuer on a self-signed certificate.

Providers: azure_event_hub,microsoft_defender


tls.cipher

Negotiated TLS cipher suite. Suites naming RC4 or MD5 indicate a weak negotiation.

Providers: azure_event_hub,microsoft_defender


tls.version

Negotiated TLS protocol version, for example TLSv10, TLSv12 or TLSv13. TLSv10 and TLSv11 are deprecated by RFC 8996.

Providers: azure_event_hub,microsoft_defender



Did this page help you?